CVE-2022-42747

MEDIUM NUCLEI

Auieo Candidats - XSS

Title source: rule

Description

CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

Nuclei Templates (1)

CandidATS 3.0.0 - Cross-Site Scripting.
MEDIUMVERIFIEDby arafatansari
Shodan: http.html:"CandidATS" || http.html:"candidats"
FOFA: body="candidats"

Scores

CVSS v3 6.1
EPSS 0.0271
EPSS Percentile 86.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
auieo/candidats 3.0.0
Published Nov 03, 2022
Tracked Since Feb 18, 2026