CVE-2022-0174: Improper Validation of Specified Quantity in Input in dolibarr/dolibarr
Published Jan 10, 2022
·Updated
Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr.
Other sources
The application does not check the input of price number lead to Business Logic error through negative price amount.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<15.0.0
15.0.0
dolibarr Dolibarr Erp\/crm<15.0.0
Remediation
Event History
Jan 10, 2022
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
DescriptionSeverityWeakness
Jan 12, 2022
Advisory Published
10:54 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-0174.
2
What is the severity of CVE-2022-0174?
The severity of CVE-2022-0174 is medium (4.3).
3
What is the affected software of CVE-2022-0174?
The affected software of CVE-2022-0174 is Dolibarr ERP/CRM version up to 15.0.0.
4
What is the description of CVE-2022-0174?
CVE-2022-0174 is an improper validation vulnerability in Dolibarr ERP/CRM that allows for a business logic error through a negative price amount.
5
How do I fix CVE-2022-0174?
To fix CVE-2022-0174, update Dolibarr ERP/CRM to version 15.0.0 or higher.