PT-2022-26534 · Candidats · Candidats
Carlos Bello
·
Published
2022-11-03
·
Updated
2025-05-05
·
CVE-2022-42744
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CandidATS version 3.0.0
Description
The issue allows an external attacker to perform CRUD operations on the application databases due to incorrect validation of the
entriesPerPage parameter against SQL injection attacks.Recommendations
For CandidATS version 3.0.0, consider restricting access to the
entriesPerPage parameter to prevent SQL injection attacks until a patch is available. As a temporary workaround, avoid using the entriesPerPage parameter in sensitive operations.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Candidats