Sceawere
Vulnerability Detail
CVE-2015-20122UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Seeyon A6 Unauthenticated SQL Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 10h ago
- Vendor
- Yonyou
- Product
- A6 OA
- Attack Type
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database contents without prior authentication. Attackers can inject UNION-based SQL statements through the attach_ids request parameter in downloadAtt.jsp to retrieve sensitive information including credentials and system configuration data. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-17.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-29T15:17:11.023Z",
"pubdate": "2026-09-29T15:17:11.023Z",
"executiveSummary": "The Seeyon A6 collaborative office automation platform is susceptible to an unauthenticated SQL injection vulnerability located within the file attachment download functionality.\nThis vulnerability allows remote, unauthenticated attackers to execute arbitrary SQL queries against the backend database by manipulating the attach_ids parameter in the downloadAtt.jsp endpoint.\nThe primary risk is unauthorized data exfiltration, enabling attackers to retrieve sensitive information, including system configuration data and user credentials.\nThe vulnerability is critical due to the lack of required authentication or elevated privileges, allowing for low-complexity exploitation over the network.\nThe Shadowserver Foundation first documented evidence of active exploitation in the wild on 2023-10-17, highlighting a significant threat to organizations relying on Seeyon A6.\nSuccessful exploitation facilitates complete compromise of database contents, leading to potential lateral movement, unauthorized access to internal workflows, and full system data exposure.",
"technicalDetails": "The vulnerability originates from improper neutralization of special elements used in an SQL command within the downloadAtt.jsp file of the Seeyon A6 collaborative office automation platform.\nThe flaw specifically exists in the handling of the attach_ids parameter, which fails to implement adequate input sanitization or parameterized queries before passing user-supplied input to the database management system.\nThe exploitation process follows a standard UNION-based SQL injection pattern. An attacker initiates an HTTP request targeting the downloadAtt.jsp endpoint. By injecting a crafted payload into the attach_ids parameter, the attacker alters the logic of the underlying SQL query.\nBecause the application does not validate the input, the database interpreter executes the injected malicious SQL commands alongside the legitimate query. By utilizing the UNION operator, an attacker can append result sets from arbitrary database tables to the legitimate response, allowing for the extraction of internal database schemas, stored procedures, and sensitive plaintext or hashed credentials.\nThis vulnerability is accessible without any prior authentication, meaning it is reachable by any remote actor with network access to the target web server. No user interaction or specialized administrative privileges are required to initiate the attack.\nThe technical impact is severe; the attacker can perform database enumeration, dump comprehensive user tables, and exfiltrate critical configuration data that may facilitate further infrastructure compromise.\nPost-exploitation, the exposure of credentials and configuration settings often allows attackers to pivot deeper into the corporate network, bypass additional security controls, and establish persistence within the application environment.\nThe persistence of this vulnerability suggests a lack of robust input validation logic within the file management component of the Seeyon A6 platform, making the application highly sensitive to query manipulation via standard HTTP GET or POST requests."
}