CVE-2022-22293: XSS
Published Jan 1, 2022
·Updated
admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAINMAXDECIMALSTOT parameter.
Affected Software
1 affected component
dolibarr Dolibarr Erp\/crm=7.0.2
Event History
Jan 1, 2022
CVE Published
via MITRE·11:52 PM
Data Sourced
via MITRE·11:52 PM
Description
Jan 2, 2022
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Dolibarr issue?
The vulnerability ID for this Dolibarr issue is CVE-2022-22293.
2
What is the severity rating of CVE-2022-22293?
CVE-2022-22293 has a severity rating of medium (5.4).
3
Which version of Dolibarr is affected by CVE-2022-22293?
Dolibarr version 7.0.2 is affected by CVE-2022-22293.
4
What is the main issue with CVE-2022-22293?
The main issue with CVE-2022-22293 is HTML injection in admin/limits.php.
5
How can I fix the HTML injection issue in Dolibarr 7.0.2?
To fix the HTML injection issue in Dolibarr 7.0.2, it is recommended to upgrade to a patched version of the software.