CVE-2012-4570: Letodms Project Letodms
Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.
SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Affected products
- Letodms Project Letodms: up to and including 3.3.7
Published 2017-10-23. Last modified 2026-06-16.