VendorsSalonERP Projectsalonerp3.0.2
Vulnerabilities

SalonERP Project SalonERP 3.0.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2022-42753
SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.
Published 2022-11-03 · Modified
6.1EPSS 0.005