CVE-2022-4093
SQL injection in Dolibarr
9.8
CRITICAL
CVSS 3.1
EPSS 0.32%
Description
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In some cases, an attacker can obtain a persistent backdoor into an organization's systems, leading to a long-term compromise that can go unnoticed for an extended period. This affect 16.0.1 and 16.0.2 only. 16.0.0 or lower, and 16.0.3 or higher are not affected
How to fix CVE-2022-4093
To remediate CVE-2022-4093, upgrade the affected package to a fixed version below.
- —no fix listed
- —upgrade to 16.0.3 or later
Is CVE-2022-4093 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 16.0.1, <= 16.0.1, >= 16.0.2, <= 16.0.2
- >= 16.0.1, < 16.0.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |