Dolibarr · Dolibarr · CVE-2022-22293
**Name of the Vulnerable Software and Affected Versions**
Dolibarr version 7.0.2
**Description**
The issue allows HTML injection, as demonstrated by the `MAIN MAX DECIMALS TOT` parameter in the "admin/limits.php" endpoint.
**Recommendations**
For Dolibarr version 7.0.2, consider restricting access to the "admin/limits.php" endpoint until a patch is available, and avoid using the `MAIN MAX DECIMALS TOT` parameter to minimize the risk of exploitation.