← voltar
CVE-2022-42746

CVE-2022-42746

CVSS 6.1 MEDIUMEPSS 1.1%CWE-79
CandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Produtos afetados
n/a · CandidATS

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →