Логотип exploitDog
bind:CVE-2022-42749
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-42749

Количество 2

Количество 2

nvd логотип

CVE-2022-42749

больше 3 лет назад

CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-8v8c-wrxg-38v2

больше 3 лет назад

CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-42749

CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVSS3: 6.1
3%
Низкий
больше 3 лет назад
github логотип
GHSA-8v8c-wrxg-38v2

CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVSS3: 6.1
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу