VYPR

Candidats

by Auieo

CVEs (2)

  • CVE-2022-42751HigNov 3, 2022
    risk 0.57cvss 8.8epss 0.00

    CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.

  • CVE-2020-9341HigFeb 22, 2020
    risk 0.57cvss 8.8epss 0.01

    CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI.