ZeroHour

CVE-2022-42745

PoC
CVSS 3.1
7.5 high
EPSS
<1%p57
Published
()
Modified
Description

CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because the application is vulnerable to XXE.

Vendors
auieosoftware
Products
candidats
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.