Логотип exploitDog
bind:CVE-2022-42750
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-42750

Количество 2

Количество 2

nvd логотип

CVE-2022-42750

больше 3 лет назад

CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the files uploaded by the user.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-6jrf-5qcg-qcqx

больше 3 лет назад

CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the files uploaded by the user.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-42750

CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the files uploaded by the user.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-6jrf-5qcg-qcqx

CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the files uploaded by the user.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу