Executive brief
A SQL injection vulnerability exists in GG Soft PaperWork, a document management and workflow automation platform. An authenticated attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive corporate documents or the disruption of business operations. The issue has been addressed in version 6.1.0.9398.
Technical details
A SQL injection vulnerability (CWE-89/CWE-564) exists in GG Soft PaperWork versions 6.1.0.9390 through 6.1.0.9397. The flaw stems from improper neutralization of special elements used in SQL commands within the Hibernate framework, allowing for both standard and Blind SQL injection. An attacker with low-privileged network access can execute arbitrary SQL queries against the backend database. This can result in full data exfiltration, modification of records, or administrative bypass. The vulnerability is resolved in version 6.1.0.9398.
Affected products
- GG Soft Software Services Inc. PaperWork 6.1.0.9390 to 6.1.0.9397
Timeline
- 2025-11-07: disclosed
- 2025-11-07: advisory