OS Command Execution Vulnerabilities in LogicalDOC Enterprise by LogicalDOC
CVE-2019-25257
Key Information:
- Vendor
Logicaldoc Srl
- Status
- Vendor
- CVE Published:
- 24 December 2025
Badges
What is CVE-2019-25257?
LogicalDOC Enterprise version 7.7.4 is vulnerable to multiple authenticated OS command execution flaws, which can be exploited by malicious actors to modify system configurations. By altering settings for binary paths, such as antivirus commands and OCR engine paths, attackers can execute arbitrary system commands with elevated privileges, potentially compromising the security and integrity of the affected system.
Affected Version(s)
LogicalDOC Enterprise 7.7.4
LogicalDOC Enterprise 7.7.3
LogicalDOC Enterprise 7.7.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
