← Vulnerability feed

Vulnerability record · CVE-2025-12547 · published 31 October 2025

CVE-2025-12547: Logicaldoc improper restriction of authentication attempts vulnerability

Logicaldoc · Logicaldoc

A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of the file /login.jsp of the component Admin Login Page. Such manipulation leads to improper restriction of excessive authentication attempts. The attack can be executed remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

2.9 CVSS 4.0 Low EPSS 0.81% · top 44.8% CWE-307 · Improper restriction of authentication attemptsCWE-799 · CWE-799
2.9CVSS 4.0 base score, v2 2.6
0.81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability affects unknown code of the file /login.jsp of the component Admin Login Page. Such manipulation leads to improper restriction of excessive authentication attempts. The attack can be executed remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://gist.github.com/thezeekhan/869aeb01bd981667c35dcac3e72c2bfa ExploitThird Party Advisory
https://vuldb.com/?ctiid.330807 Permissions RequiredVDB Entry
https://vuldb.com/?id.330807 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.677172 Third Party AdvisoryVDB Entry

Track CVE-2025-12547 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-9423Logicaldoc unrestricted file upload vulnerabilityLogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. Logic…EPSS 5.0%8.8CVE-2017-1000021Logicaldoc xml external entity (xxe) vulnerabilityLogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.EPSS 1.2%8.8CVE-2017-1000022Logicaldoc incorrect permission assignment vulnerabilityLogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation.EPSS 1.2%8.7CVE-2024-54449Logicaldoc relative path traversal vulnerabilityThe API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file w…EPSS 0.60%8.6CVE-2024-54448Logicaldoc code injection vulnerabilityThe Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account …EPSS 0.56%7.8CVE-2020-13542Logicaldoc incorrect default permissions vulnerabilityA local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depending on the vector chosen, an …EPSS 0.61%7.5CVE-2020-10366Logicaldoc path traversal vulnerabilityLogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-2020-10365.EPSS 1.5%7.1CVE-2019-25258Logicaldoc path traversal vulnerabilityLogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files throug…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2025-12547), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.