PoC Index

CVE-2022-42747

MEDIUM 6.1EPSS 1.1%

CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.08% chance of exploitation in the next 30 days, 63th percentile
Nuclei
medium · CWE-79
Published
2022-11-03
Updated
2025-05-05

Nuclei templates (1)

References

Related