Lucene search

K
cvelistFluid AttacksCVELIST:CVE-2022-42753
HistoryNov 03, 2022 - 12:00 a.m.

CVE-2022-42753

2022-11-0300:00:00
Fluid Attacks
www.cve.org
3
salonerp
cookie theft
validation
xss attacks

EPSS

0.001

Percentile

36.9%

SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "SalonERP",
    "versions": [
      {
        "version": "3.0.2",
        "status": "affected"
      }
    ]
  }
]

EPSS

0.001

Percentile

36.9%

Related for CVELIST:CVE-2022-42753