PT-2022-25628 · Softwarex · Softwarex

Eldy

·

Published

2022-11-21

·

Updated

2025-04-03

·

CVE-2022-4093

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SoftwareX versions 16.0.1 through 16.0.2
Description SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In some cases, an attacker can obtain a persistent backdoor into an organization's systems, leading to a long-term compromise that can go unnoticed for an extended period.
Recommendations For versions 16.0.1 and 16.0.2, update to version 16.0.3 or higher to resolve the issue. As a temporary workaround, consider restricting access to sensitive data and implementing additional security measures to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BIT-DOLIBARR-2022-4093
CVE-2022-4093
GHSA-GJG7-QFVP-9HM4

Affected Products

Softwarex