CVE-2022-42753
PoC —CVSS 3.1
6.1 medium
EPSS
<1%p38
Published
()
Modified
Description
SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.
- Vendors
- salonerp project
- Products
- salonerp
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.