CVE-2022-42744 Vulnerability Details
/
/
/
CVE-2022-42744 Metadata Quick Info
CVE Published: 03/11/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022
Source: Fluid Attacks |
Vendor: n/a |
Product: CandidATS
Status : PUBLISHED
CVE-2022-42744 Description
CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application does not correctly validate the entriesPerPage parameter against SQLi attacks.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID:
CWE Name: SQL injection
Source: n/a
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).