{"id":"CVE-2019-25684","title":"OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter","summary":"OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicio…","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","cwe":["CWE-89"],"vendor":"opendocman","product":"opendocman","affected":["opendocman <= 1.3.4"],"published":"2026-04-05","updated":"2026-10-06","sourceUpdated":"2026-10-06T22:10:00.247","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-25684","references":[{"url":"https://sourceforge.net/projects/opendocman/files/","label":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/46500","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/opendocman-sql-injection-via-where-parameter","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.00327,"epssPercentile":0.23631,"ingestedAt":"2026-10-06T22:23:15.918Z","slug":"CVE-2019-25684","body":"## Overview\n\nOpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to extract sensitive database information.\n\n## Affected\n\n- `opendocman <= 1.3.4`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":45.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}