{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aseeyona6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:seeyon:a6:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2015-20122"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["A6"],"_cs_severities":["high"],"_cs_tags":["sqli","vulnerability","webserver"],"_cs_type":"threat","_cs_vendors":["Seeyon"],"content_html":"\u003cp\u003eSeeyon A6 collaborative office automation platform is vulnerable to an unauthenticated SQL injection vulnerability (CVE-2015-20122). This vulnerability resides in the attach_ids parameter of the downloadAtt.jsp file attachment download endpoint. Remote attackers can leverage this flaw to perform UNION-based SQL injection attacks without requiring prior authentication. By crafting malicious input for the attach_ids parameter, attackers can extract sensitive database information, including credentials and system configuration data. The Shadowserver Foundation first observed evidence of exploitation in the wild on October 17, 2023. Given the sensitivity of the data typically stored in collaborative office automation platforms, this vulnerability presents a significant risk to organizational confidentiality and integrity.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized retrieval of sensitive information from the underlying database, including system credentials and configuration settings. This can lead to full compromise of the application, lateral movement within the network, and the potential exfiltration of proprietary or sensitive business documentation stored within the collaborative environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit web server logs for suspicious POST or GET requests to /downloadAtt.jsp containing SQL keywords (e.g., UNION, SELECT, OR, SLEEP) in the attach_ids parameter.\u003c/li\u003e\n\u003cli\u003eApply the latest security patches provided by Seeyon for the A6 platform to remediate CVE-2015-20122.\u003c/li\u003e\n\u003cli\u003eRestrict access to the file attachment download functionality at the network or web application firewall level if patching is not immediately feasible.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-29T16:28:27Z","date_published":"2026-09-29T16:28:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-seeyon-a6-sqli/","summary":"Seeyon A6 contains an unauthenticated SQL injection vulnerability in the downloadAtt.jsp endpoint, allowing remote attackers to extract sensitive database contents via the attach_ids parameter.","title":"Unauthenticated SQL Injection in Seeyon A6","url":"https://feed.craftedsignal.io/briefs/2026-09-seeyon-a6-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:seeyon:a6:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}