CVE-2022-42745

HIGH

CandidATS 3.0.0 - XML External Entity Injection

Title source: llm
STIX 2.1

Description

CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because the application is vulnerable to XXE.

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://fluidattacks.com/advisories/jcole/

Scores

CVSS v3 7.5
EPSS 0.0080
EPSS Percentile 51.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (1)
auieosoftware/candidats 3.0.0
Published Nov 03, 2022
Tracked Since Feb 18, 2026