PatchSiren

opendocman CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH opendocman CVE published 2026-04-05

CVE-2019-25684

CVE-2019-25684 is an SQL injection vulnerability in OpenDocMan 1.3.4. The vulnerability allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter in search.php. Attackers can send GET requests with malicious SQL payloads to extract sensitive database information. This vulnerability has significant implications for the security of OpenDocMan 1.3.4 d [truncated]