CVE-2022-47415: LogicalDOC Messaging Stored XSS
Published Feb 7, 2023
·Updated
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the in-app messaging system (both subject and message bodies).
Affected Software
2 affected components
LogicalDOC LogicalDOC=8.7.3
LogicalDOC LogicalDOC=8.8.2
Event History
Feb 7, 2023
CVE Published
via MITRE·09:33 PM
Data Sourced
via MITRE·09:33 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-47415?
CVE-2022-47415 has a medium severity due to its persistent cross-site scripting vulnerability affecting user input in the messaging system.
2
How do I fix CVE-2022-47415?
To fix CVE-2022-47415, update to the latest version of LogicalDOC which addresses the stored XSS vulnerability.
3
What versions of LogicalDOC are affected by CVE-2022-47415?
CVE-2022-47415 affects LogicalDOC versions 8.7.3 Community Edition and 8.8.2 Enterprise Edition.
4
What type of vulnerability is CVE-2022-47415?
CVE-2022-47415 is classified as a stored cross-site scripting (XSS) vulnerability.
5
Where is CVE-2022-47415 found in LogicalDOC?
CVE-2022-47415 is found in the in-app messaging system, specifically in the subject and message bodies.