ZeroHour

CVE-2022-42744

PoC
CVSS 3.1
9.8 critical
EPSS
1%p68
Published
()
Modified
Description

CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application does not correctly validate the entriesPerPage parameter against SQLi attacks.

Vendors
auieo
Products
candidats
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.