CVE-2024-12020: Logicaldoc

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthenticated attacker could deceive a user into clicking a crafted link to trigger the vulnerability. Stealing the session cookie is not possible due to cookie security flags, however the XSS may be used to induce a victim to perform on-site requests without their knowledge. This vulnerability only affects LogicalDOC Enterprise.

Affected products

Published 2025-03-14. Last modified 2026-06-17.