Логотип exploitDog
bind:CVE-2022-42753
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-42753

Количество 2

Количество 2

nvd логотип

CVE-2022-42753

больше 3 лет назад

SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4cm4-r3q9-95wh

больше 3 лет назад

SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-42753

SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4cm4-r3q9-95wh

SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу