VYPR
Vendor

CandidATS

Products
1
CVEs
7
Across products
7
Status
Private

Products

1

Recent CVEs

7
  • CVE-2022-42749Nov 3, 2022
    risk 0.00cvss epss 0.03

    CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

  • CVE-2022-42746Nov 3, 2022
    risk 0.00cvss epss 0.03

    CandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

  • CVE-2022-42747Nov 3, 2022
    risk 0.00cvss epss 0.03

    CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

  • CVE-2022-42744Nov 3, 2022
    risk 0.00cvss epss 0.01

    CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application does not correctly validate the entriesPerPage parameter against SQLi attacks.

  • CVE-2022-42750Nov 3, 2022
    risk 0.00cvss epss 0.01

    CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the files uploaded by the user.

  • CVE-2022-42751Nov 3, 2022
    risk 0.00cvss epss 0.00

    CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.

  • CVE-2022-42748Nov 3, 2022
    risk 0.00cvss epss 0.03

    CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.