Vulnerabilities (CVE)

Filtered by vendor Auieo Subscribe
Filtered by product Candidats
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-42745 1 Auieo 1 Candidats 2023-08-08 N/A 7.5 HIGH
CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because the application is vulnerable to XXE.
CVE-2020-9341 1 Auieo 1 Candidats 2020-02-24 6.8 MEDIUM 8.8 HIGH
CandidATS 2.1.0 is vulnerable to CSRF that allows for an administrator account to be added via the index.php?m=settings&a=addUser URI.