Skip to content
Threat Feed
high threat exploited

Unauthenticated SQL Injection in Seeyon A6

Seeyon A6 contains an unauthenticated SQL injection vulnerability in the downloadAtt.jsp endpoint, allowing remote attackers to extract sensitive database contents via the attach_ids parameter.

CVE search metadata

CVE search record: CVE-2015-20122. Severity: high. CVSS: 7.5. KEV: no. Product: A6. Brief: Unauthenticated SQL Injection in Seeyon A6. Brief link: https://feed.craftedsignal.io/briefs/2026-09-seeyon-a6-sqli/

Seeyon A6 collaborative office automation platform is vulnerable to an unauthenticated SQL injection vulnerability (CVE-2015-20122). This vulnerability resides in the attach_ids parameter of the downloadAtt.jsp file attachment download endpoint. Remote attackers can leverage this flaw to perform UNION-based SQL injection attacks without requiring prior authentication. By crafting malicious input for the attach_ids parameter, attackers can extract sensitive database information, including credentials and system configuration data. The Shadowserver Foundation first observed evidence of exploitation in the wild on October 17, 2023. Given the sensitivity of the data typically stored in collaborative office automation platforms, this vulnerability presents a significant risk to organizational confidentiality and integrity.

Impact

Successful exploitation allows for the unauthorized retrieval of sensitive information from the underlying database, including system credentials and configuration settings. This can lead to full compromise of the application, lateral movement within the network, and the potential exfiltration of proprietary or sensitive business documentation stored within the collaborative environment.

Recommendation

  1. Audit web server logs for suspicious POST or GET requests to /downloadAtt.jsp containing SQL keywords (e.g., UNION, SELECT, OR, SLEEP) in the attach_ids parameter.
  2. Apply the latest security patches provided by Seeyon for the A6 platform to remediate CVE-2015-20122.
  3. Restrict access to the file attachment download functionality at the network or web application firewall level if patching is not immediately feasible.

Immediate actions

Scan web server access logs for requests to downloadAtt.jsp with UNION-based SQL injection strings in attach_ids.

SOC 24h

Mitigations

Upgrade or patch Seeyon A6 to a version that addresses CVE-2015-20122.

immediate IT Operations

CVE-2015-20122