PT-2022-15338 · Dolibarr · Dolibarr

Mustgundogdu

·

Published

2022-01-01

·

Updated

2025-04-03

·

CVE-2022-22293

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dolibarr version 7.0.2
Description The issue allows HTML injection, as demonstrated by the MAIN MAX DECIMALS TOT parameter in the "admin/limits.php" endpoint.
Recommendations For Dolibarr version 7.0.2, consider restricting access to the "admin/limits.php" endpoint until a patch is available, and avoid using the MAIN MAX DECIMALS TOT parameter to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-DOLIBARR-2022-22293
CVE-2022-22293
GHSA-G5JM-XHWM-9XP9

Affected Products

Dolibarr