PT-2022-13010 · Dolibarr · Dolibarr

Published

2022-01-10

·

Updated

2025-04-03

·

CVE-2022-0174

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions dolibarr (affected versions not specified)
Description The issue concerns an improper validation of specified quantity in input, leading to business logic errors. This occurs because the application does not check the input of price numbers, allowing for negative price amounts to be processed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

BIT-DOLIBARR-2022-0174
CVE-2022-0174
GHSA-8QVX-F5GF-G43V

Affected Products

Dolibarr