HTML Injection Vulnerability in Dolibarr by Dolibarr Solutions
CVE-2022-22293

5.4MEDIUM

Key Information:

Vendor

Dolibarr

Vendor
CVE Published:
2 January 2022

What is CVE-2022-22293?

The HTML injection vulnerability found in Dolibarr version 7.0.2 allows attackers to manipulate input parameters, specifically through the MAIN_MAX_DECIMALS_TOT parameter in admin/limits.php. Such exploitation could lead to unauthorized execution of arbitrary HTML, potentially compromising user data and security. Proper validation and sanitization methods should be implemented to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.