VendorsSalonERP Projectsalonerpall versions
Vulnerabilities

SalonERP Project SalonERP

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2021-45406
In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password.
Published 2022-01-14 · Modified
8.8EPSS 0.018
CVE-2022-42753
SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.
Published 2022-11-03 · Modified
6.1EPSS 0.005