PT-2022-26543 · Salonerp · Salonerp

Carlos Bello

·

Published

2022-11-03

·

Updated

2025-05-06

·

CVE-2022-42753

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SalonERP version 3.0.2
Description The issue allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.
Recommendations For SalonERP version 3.0.2, update the application to correctly validate the page parameter to prevent XSS attacks. As a temporary workaround, consider restricting access to sensitive user data to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-42753

Affected Products

Salonerp