Unauthenticated SQL Injection in Seeyon A6
Seeyon A6 contains an unauthenticated SQL injection vulnerability in the downloadAtt.jsp endpoint, allowing remote attackers to extract sensitive database contents via the attach_ids parameter.
CVE search metadata
CVE search record: CVE-2015-20122. Severity: high. CVSS: 7.5. KEV: no. Product: A6. Brief: Unauthenticated SQL Injection in Seeyon A6. Brief link: https://feed.craftedsignal.io/briefs/2026-09-seeyon-a6-sqli/
Seeyon A6 collaborative office automation platform is vulnerable to an unauthenticated SQL injection vulnerability (CVE-2015-20122). This vulnerability resides in the attach_ids parameter of the downloadAtt.jsp file attachment download endpoint. Remote attackers can leverage this flaw to perform UNION-based SQL injection attacks without requiring prior authentication. By crafting malicious input for the attach_ids parameter, attackers can extract sensitive database information, including credentials and system configuration data. The Shadowserver Foundation first observed evidence of exploitation in the wild on October 17, 2023. Given the sensitivity of the data typically stored in collaborative office automation platforms, this vulnerability presents a significant risk to organizational confidentiality and integrity.
Impact
Successful exploitation allows for the unauthorized retrieval of sensitive information from the underlying database, including system credentials and configuration settings. This can lead to full compromise of the application, lateral movement within the network, and the potential exfiltration of proprietary or sensitive business documentation stored within the collaborative environment.
Recommendation
- Audit web server logs for suspicious POST or GET requests to /downloadAtt.jsp containing SQL keywords (e.g., UNION, SELECT, OR, SLEEP) in the attach_ids parameter.
- Apply the latest security patches provided by Seeyon for the A6 platform to remediate CVE-2015-20122.
- Restrict access to the file attachment download functionality at the network or web application firewall level if patching is not immediately feasible.
Immediate actions
Scan web server access logs for requests to downloadAtt.jsp with UNION-based SQL injection strings in attach_ids.
Mitigations
Upgrade or patch Seeyon A6 to a version that addresses CVE-2015-20122.
CVE-2015-20122