Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2022-42745
Disclosure Date: November 03, 2022 (last updated February 24, 2025)
CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because the application is vulnerable to XXE.
0
Attacker Value
Unknown
CVE-2022-42747
Disclosure Date: November 03, 2022 (last updated February 24, 2025)
CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.
0
Attacker Value
Unknown
CVE-2022-42744
Disclosure Date: November 03, 2022 (last updated February 24, 2025)
CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application does not correctly validate the entriesPerPage parameter against SQLi attacks.
0
Attacker Value
Unknown
CVE-2022-42749
Disclosure Date: November 03, 2022 (last updated February 24, 2025)
CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.
0
Attacker Value
Unknown
CVE-2022-42746
Disclosure Date: November 03, 2022 (last updated February 24, 2025)
CandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.
0
Attacker Value
Unknown
CVE-2022-42748
Disclosure Date: November 03, 2022 (last updated February 24, 2025)
CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.
0
Attacker Value
Unknown
CVE-2022-42751
Disclosure Date: November 03, 2022 (last updated February 24, 2025)
CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.
0
Attacker Value
Unknown
CVE-2022-42750
Disclosure Date: November 03, 2022 (last updated February 24, 2025)
CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the files uploaded by the user.
0
Attacker Value
Unknown
CVE-2022-25228
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
CandidATS Version 3.0.0 Beta allows an authenticated user to inject SQL queries in '/index.php?m=settings&a=show' via the 'userID' parameter, in '/index.php?m=candidates&a=show' via the 'candidateID', in '/index.php?m=joborders&a=show' via the 'jobOrderID' and '/index.php?m=companies&a=show' via the 'companyID' parameter
0
Attacker Value
Unknown
CVE-2020-9341
Disclosure Date: February 22, 2020 (last updated February 21, 2025)
CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI.
0