ZeroHour

CVE-2022-42751

PoC
CVSS 3.1
8.8 high
EPSS
<1%p38
Published
()
Modified
Description

CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.

Vendors
auieo
Products
candidats
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.