CVE-2022-42748
28Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 6.1epss 1.1%
exploitation probability
1.1%top 35% of all CVEs
observed exploitation
nono source reports it
CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
n/a · CandidATS