CVE-2022-47418: LogicalDOC Document Version Comment Stored XSS
LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the document version comments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-47418?
CVE-2022-47418 has a medium severity rating due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2022-47418?
To fix CVE-2022-47418, upgrade to the latest versions of LogicalDOC Enterprise or Community Edition that patch this vulnerability.
What software versions are affected by CVE-2022-47418?
CVE-2022-47418 affects LogicalDOC Community Edition version 8.7.3 and LogicalDOC Enterprise Edition version 8.8.2.
What type of vulnerability is CVE-2022-47418?
CVE-2022-47418 is a stored cross-site scripting (XSS) vulnerability that can lead to the injection of malicious scripts.
How does CVE-2022-47418 impact users?
CVE-2022-47418 can lead to unauthorized actions by exploiting the XSS vulnerability through manipulated document comments.