← Vulnerability feed

Vulnerability record · CVE-2024-54448 · published 14 March 2025

CVE-2024-54448: Logicaldoc code injection vulnerability

Logicaldoc · Logicaldoc

The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account with administrator privileges or that has been explicitly granted access to use Automation Scripting is needed to carry out the attack. Exploitation of this vulnerability would allow an attacker to run commands of their choosing on the underlying operating system of the web server running LogicalDOC.

8.6 CVSS 4.0 High EPSS 0.56% · top 55.4% CWE-94 · Code injection
8.6CVSS 4.0 base score
0.56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
26 Aug 2026Last modified by NVD

Description

The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account with administrator privileges or that has been explicitly granted access to use Automation Scripting is needed to carry out the attack. Exploitation of this vulnerability would allow an attacker to run commands of their choosing on the underlying operating system of the web server running LogicalDOC.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-54448 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-9423Logicaldoc unrestricted file upload vulnerabilityLogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. Logic…EPSS 5.0%8.8CVE-2017-1000021Logicaldoc xml external entity (xxe) vulnerabilityLogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.EPSS 1.2%8.8CVE-2017-1000022Logicaldoc incorrect permission assignment vulnerabilityLogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation.EPSS 1.2%8.7CVE-2024-54449Logicaldoc relative path traversal vulnerabilityThe API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file w…EPSS 0.60%7.8CVE-2020-13542Logicaldoc incorrect default permissions vulnerabilityA local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depending on the vector chosen, an …EPSS 0.61%7.5CVE-2020-10366Logicaldoc path traversal vulnerabilityLogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-2020-10365.EPSS 1.5%7.1CVE-2019-25258Logicaldoc path traversal vulnerabilityLogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files throug…EPSS 1.1%7.1CVE-2019-9723Logicaldoc path traversal vulnerabilityLogicalDOC Community Edition 8.x before 8.2.1 has a path traversal vulnerability that allows reading arbitrary files and the creation of directories,…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2024-54448), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.