← volver
CVE-2022-42748mediumCWE-79

CVE-2022-42748

28Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 6.1epss 1.1%
probabilidad de explotación
1.1%top 36% de las CVE
explotación observada
noninguna fuente lo reporta
CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Productos afectados
n/a · CandidATS