CVE-2022-42749

MEDIUM NUCLEI

CandidATS 3.0.0 - Cross-Site Scripting via ajax.php Page Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-42749 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

Nuclei Templates (1)

CandidATS 3.0.0 - Cross-Site Scripting
MEDIUMVERIFIEDby arafatansari
Shodan: http.html:"CandidATS" || http.html:"candidats"
FOFA: body="candidats"

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://fluidattacks.com/advisories/modestep/

Scores

CVSS v3 6.1
EPSS 0.0107
EPSS Percentile 60.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
auieo/candidats 3.0.0
Published Nov 03, 2022
Tracked Since Feb 18, 2026