<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:seeyon:a6:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aseeyona6/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 16:28:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aseeyona6/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated SQL Injection in Seeyon A6</title><link>https://feed.craftedsignal.io/briefs/2026-09-seeyon-a6-sqli/</link><pubDate>Tue, 29 Sep 2026 16:28:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-seeyon-a6-sqli/</guid><description>Seeyon A6 contains an unauthenticated SQL injection vulnerability in the downloadAtt.jsp endpoint, allowing remote attackers to extract sensitive database contents via the attach_ids parameter.</description><content:encoded><![CDATA[<p>Seeyon A6 collaborative office automation platform is vulnerable to an unauthenticated SQL injection vulnerability (CVE-2015-20122). This vulnerability resides in the attach_ids parameter of the downloadAtt.jsp file attachment download endpoint. Remote attackers can leverage this flaw to perform UNION-based SQL injection attacks without requiring prior authentication. By crafting malicious input for the attach_ids parameter, attackers can extract sensitive database information, including credentials and system configuration data. The Shadowserver Foundation first observed evidence of exploitation in the wild on October 17, 2023. Given the sensitivity of the data typically stored in collaborative office automation platforms, this vulnerability presents a significant risk to organizational confidentiality and integrity.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the unauthorized retrieval of sensitive information from the underlying database, including system credentials and configuration settings. This can lead to full compromise of the application, lateral movement within the network, and the potential exfiltration of proprietary or sensitive business documentation stored within the collaborative environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Audit web server logs for suspicious POST or GET requests to /downloadAtt.jsp containing SQL keywords (e.g., UNION, SELECT, OR, SLEEP) in the attach_ids parameter.</li>
<li>Apply the latest security patches provided by Seeyon for the A6 platform to remediate CVE-2015-20122.</li>
<li>Restrict access to the file attachment download functionality at the network or web application firewall level if patching is not immediately feasible.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>sqli</category><category>vulnerability</category><category>webserver</category></item></channel></rss>