Product
Seeyon A6 contains an unauthenticated SQL injection vulnerability in the downloadAtt.jsp endpoint, allowing remote attackers to extract sensitive database contents via the attach_ids parameter.