ZeroHour

CVE-2022-42753

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p38
Published
()
Modified
Description

SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.

Vendors
salonerp project
Products
salonerp
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.