Логотип exploitDog
bind:CVE-2022-42748
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-42748

Количество 2

Количество 2

nvd логотип

CVE-2022-42748

больше 3 лет назад

CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-5587-9qwv-rggc

больше 3 лет назад

CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-42748

CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVSS3: 6.1
3%
Низкий
больше 3 лет назад
github логотип
GHSA-5587-9qwv-rggc

CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVSS3: 6.1
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу