CVE-2022-47417: LogicalDOC Document File Name Stored XSS
Published Feb 7, 2023
·Updated
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the document file name.
Affected Software
2 affected components
LogicalDOC LogicalDOC=8.7.3
LogicalDOC LogicalDOC=8.8.2
Event History
Feb 7, 2023
CVE Published
via MITRE·09:59 PM
Data Sourced
via MITRE·09:59 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-47417?
CVE-2022-47417 has a medium severity rating as it can lead to stored cross-site scripting vulnerabilities.
2
How do I fix CVE-2022-47417?
To fix CVE-2022-47417, update LogicalDOC to the latest version that addresses the XSS vulnerability.
3
What versions of LogicalDOC are affected by CVE-2022-47417?
CVE-2022-47417 affects LogicalDOC Community Edition version 8.7.3 and Enterprise Edition version 8.8.2.
4
What types of attacks are possible with CVE-2022-47417?
CVE-2022-47417 enables attackers to execute harmful scripts in the context of an authenticated user's session.
5
Is user data at risk due to CVE-2022-47417?
Yes, user data is at risk since the persistent XSS vulnerability can lead to data theft and session hijacking.