AuieoCVEs & Vulnerabilities

9 CVEs affecting Auieo products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

candidats 9
CVE-2022-42749MEDIUM

CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

3 Nov 2022
6.1
CVSS
CVE-2022-42748MEDIUM

CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

3 Nov 2022
6.1
CVSS
CVE-2022-42747MEDIUM

CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

3 Nov 2022
6.1
CVSS
CVE-2022-42746MEDIUM

CandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

3 Nov 2022
6.1
CVSS
CVE-2022-42744CRITICAL

CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is possible because the application does not correctly validate the entriesPerPage parameter against SQLi attacks.

3 Nov 2022
9.8
CVSS
CVE-2022-42751HIGH

CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.

3 Nov 2022
8.8
CVSS
CVE-2022-42750HIGH

CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the files uploaded by the user.

3 Nov 2022
8.8
CVSS
CVE-2022-25228MEDIUM

CandidATS Version 3.0.0 Beta allows an authenticated user to inject SQL queries in '/index.php?m=settings&a=show' via the 'userID' parameter, in '/index.php?m=candidates&a=show' via the 'candidateID', in '/index.php?m=joborders&a=show' via the 'jobOrderID' and '/index.php?m=companies&a=show' via the 'companyID' parameter

18 Aug 2022
6.5
CVSS
CVE-2020-9341HIGH

CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI.

23 Feb 2020
8.8
CVSS
← PrevPage 1 / 1Next →
Auieo CVEs & Vulnerabilities — 9 Tracked