CVE-2022-42751
03.11.2022, 18:15
CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.
Vendor | Product | Version |
---|---|---|
auieo | candidats | 3.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration