Known Vulnerabilities for products from Auieo
Listed below are 10 of the newest known vulnerabilities associated with the vendor "Auieo".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-42751 json | CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the ap... | 8.8 - HIGH | 2022-11-03 | 2022-11-04 |
| CVE-2022-42750 json | CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the appl... | 8.8 - HIGH | 2022-11-03 | 2022-11-04 |
| CVE-2022-42749 json | CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary us... | 6.1 - MEDIUM | 2022-11-03 | 2023-11-07 |
| CVE-2022-42748 json | CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arb... | 6.1 - MEDIUM | 2022-11-03 | 2023-11-07 |
| CVE-2022-42747 json | CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary ... | 6.1 - MEDIUM | 2022-11-03 | 2023-11-07 |
| CVE-2022-42746 json | CandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitra... | 6.1 - MEDIUM | 2022-11-03 | 2023-11-07 |
| CVE-2022-42745 json | CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because the app... | 7.5 - HIGH | 2022-11-03 | 2023-08-08 |
| CVE-2022-42744 json | CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible... | 9.8 - CRITICAL | 2022-11-03 | 2022-11-05 |
| CVE-2022-25228 json | CandidATS Version 3.0.0 Beta allows an authenticated user to inject SQL queries in '/index.php?m=settings&a=show' via the 'us... | 6.5 - MEDIUM | 2022-08-18 | 2022-08-19 |
| CVE-2020-9341 json | CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=add... | 8.8 - HIGH | 2020-02-22 | 2020-02-24 |
Known software with vulnerabilities from Auieo
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Auieo | Candidats | 2.1.0 |