Логотип exploitDog
bind:CVE-2022-42747
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-42747

Количество 2

Количество 2

nvd логотип

CVE-2022-42747

больше 3 лет назад

CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-crwf-v7hm-2cqq

больше 3 лет назад

CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-42747

CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVSS3: 6.1
3%
Низкий
больше 3 лет назад
github логотип
GHSA-crwf-v7hm-2cqq

CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVSS3: 6.1
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу