---
id: CVE-2019-25684
title: >-
  OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows
  unauthenticated attackers to manipulate database queries by injecting SQL code
  through the 'where' parameter
summary: >-
  OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows
  unauthenticated attackers to manipulate database queries by injecting SQL code
  through the 'where' parameter. Attackers can send GET requests to search.php
  with malicio…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-89
vendor: opendocman
product: opendocman
affected:
  - opendocman <= 1.3.4
published: '2026-04-05'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T22:10:00.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-25684'
references:
  - url: 'https://sourceforge.net/projects/opendocman/files/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/46500'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/opendocman-sql-injection-via-where-parameter
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00327
epssPercentile: 0.23631
ingestedAt: '2026-10-06T22:23:15.918Z'
---

## Overview

OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to extract sensitive database information.

## Affected

- `opendocman <= 1.3.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
