{"id":"CVE-2015-20122","title":"Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database co…","summary":"Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database co…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-89"],"vendor":"Yonyou","product":"A6 OA","affected":["a6_oa"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T17:17:00.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2015-20122","references":[{"url":"https://qkl.seebug.org/vuldb/ssvid-89642","label":"disclosure@vulncheck.com"},{"url":"https://www.ddpoc.com/poc/DVB-2021-2211.html","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/seeyon-a6-oa-unauthenticated-sql-injection-via-downloadatt-jsp","label":"disclosure@vulncheck.com"},{"url":"https://www.ddpoc.com/poc/DVB-2021-2211.html","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-29T16:06:31.409648Z"},"ingestedAt":"2026-09-29T16:39:33.256Z","slug":"CVE-2015-20122","body":"## Overview\n\nSeeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database contents without prior authentication. Attackers can inject UNION-based SQL statements through the attach_ids request parameter in downloadAtt.jsp to retrieve sensitive information including credentials and system configuration data. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-17.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}