CVE-2022-47416: LogicalDOC Chat Stored XSS
Published Feb 7, 2023
·Updated
LogicalDOC Enterprise is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the in-app chat system.
Affected Software
1 affected component
LogicalDOC LogicalDOC=8.8.2
Event History
Feb 7, 2023
CVE Published
via MITRE·09:46 PM
Data Sourced
via MITRE·09:46 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-47416?
CVE-2022-47416 has a medium severity rating due to its potential for exploiting stored XSS vulnerabilities.
2
How do I fix CVE-2022-47416?
To fix CVE-2022-47416, it is recommended to apply the latest security patch provided by LogicalDOC.
3
What components are affected by CVE-2022-47416?
CVE-2022-47416 affects the in-app chat system of LogicalDOC Enterprise version 8.8.2.
4
What type of vulnerability is CVE-2022-47416?
CVE-2022-47416 is classified as a stored cross-site scripting (XSS) vulnerability.
5
What are the potential impacts of CVE-2022-47416?
The potential impacts of CVE-2022-47416 include unauthorized script execution in the context of other users' sessions.