CVE-2022-4933
Summary
| CVE | CVE-2022-4933 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-20 05:15:00 UTC |
| Updated | 2023-11-07 03:59:00 UTC |
| Description | A vulnerability, which was classified as critical, has been found in ATM Consulting dolibarr_module_quicksupplierprice up to 1.1.6. Affected by this issue is the function upatePrice of the file script/interface.php. The manipulation leads to sql injection. The attack may be launched remotely. Upgrading to version 1.1.7 is able to address this issue. The patch is identified as ccad1e4282b0e393a32fcc852e82ec0e0af5446f. It is recommended to upgrade the affected component. VDB-223382 is the identifier assigned to this vulnerability. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atm-consulting | Dolibarr Module Quicksupplierprice | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Login required | MISC | vuldb.com | |
| FIX : `Interface.php` has fatal errors (invisible to user) due to SQL… · ATM-Consulting/dolibarr_module_quicksupplierprice@ccad1e4 · GitHub | MISC | github.com | |
| FIX : `Interface.php` has fatal errors (invisible to user) due to unprotected SQL injection of input vars by atm-florianm · Pull Request #21 · ATM-Consulting/dolibarr_module_quicksupplierprice · GitHub | MISC | github.com | |
| Login required | MISC | vuldb.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.