LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://blog.randorisec.fr/logicaldoc-from-guest-to-root/ | third party advisory exploit |