← voltar
CVE-2022-42748mediumCWE-79

CVE-2022-42748

28Vexday Risk Score

Corrija em breve. Ela tem exploit funcional público.

ssvc Attendcvss 6.1epss 1.1%
probabilidade de exploração
1.1%top 35% das CVEs
exploração observada
nãonenhuma fonte reporta
CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Produtos afetados
n/a · CandidATS