CVE-2022-42753
03.11.2022, 18:15
SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.
| Vendor | Product | Version |
|---|---|---|
| salonerp_project | salonerp | 3.0.2 |
𝑥
= Vulnerable software versions