Vulnerabilities > CVE-2022-42745 - XXE vulnerability in Auieosoftware Candidats 3.0.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
auieosoftware
CWE-611

Summary

CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because the application is vulnerable to XXE.

Vulnerable Configurations

Part Description Count
Application
Auieosoftware
1