Letodms Project maintains a document management system whose vulnerability profile centers on a single product with recurring web-application input-handling weaknesses including cross-site scripting, SQL injection, and cross-site request forgery. This niche, narrowly deployed system presents a contained but relevant attack surface for organizations deploying its document-storage functionality; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Letodms Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2006MEDIUM Directory traversal vulnerability in op/op.Login.php in LetoDMS (formerly MyDMS) 1.7.2 and earlier allows remote authenticated users to include and execute arbitrary local files vi | May 20, 2010 | 6.5 | 35 | NO | YES |
CVE-2012-4570CRITICAL SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified | Oct 23, 2017 | 9.8 | 31 | NO | NO |
CVE-2012-4568HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to hijack the authentication of unspecified victims via u | Oct 23, 2017 | 8.8 | 25 | NO | NO |
CVE-2010-2007MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) 1.7.2 and earlier allow remote attackers to hijack the authentication of administrators for r | May 20, 2010 | 6.8 | 23 | NO | NO |
CVE-2012-4569MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in out/out.UsrMgr.php in LetoDMS (formerly MyDMS) before 3.3.9 allow remote attackers to inject arbitrary web script or HTML via | Oct 23, 2017 | 6.1 | 20 | NO | NO |
CVE-2012-4567MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to inject arbitrary web script or HTML via unspecified parameter | Oct 23, 2017 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Letodms Project.
Media articles that mention a CVE ID that affects a product developed by Letodms Project — matched by CVE ID, not by vendor name.