CVE-2014-1945: Opendocman

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the add_value parameter.

Affected products

  • Opendocman Opendocman: up to and including 1.2.7.1; version 1.2.6.2 only; version 1.2.6.3 only; version 1.2.6.5 only; version 1.2.6.6 only; version 1.2.6.7 only; …

Published 2014-03-09. Last modified 2026-06-17.