A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the component API Key creation UI. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
History

Fri, 07 Nov 2025 01:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:logicaldoc:logicaldoc:*:*:*:*:community:*:*:*

Mon, 03 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Logicaldoc
Logicaldoc logicaldoc
Vendors & Products Logicaldoc
Logicaldoc logicaldoc

Fri, 31 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 18:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the component API Key creation UI. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title LogicalDOC Community Edition API Key creation UI cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-10-31T18:32:05.885Z

Updated: 2025-10-31T18:59:31.730Z

Reserved: 2025-10-31T13:10:09.009Z

Link: CVE-2025-12546

cve-icon Vulnrichment

Updated: 2025-10-31T18:59:00.560Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-31T19:15:49.380

Modified: 2025-11-07T01:30:56.277

Link: CVE-2025-12546

cve-icon Redhat

No data.