S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-42748 Scanner

CVE-2022-42748 scanner - Cross-Site Scripting (XSS) vulnerability in CandidATS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-42748
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
CandidATSby n/a
3.0.0
Updated Aug 22, 2026View on NVD →
Detail

CandidATS is a web-based recruitment management system designed to streamline and centralize the hiring process. It offers a range of features, including resume parsing, job management, candidate tracking, and collaboration tools. CandidATS is used by HR professionals and recruiters to simplify their workflows and improve their overall productivity. However, a recently discovered vulnerability in the system has raised concerns regarding the security of user data.

The CVE-2022-42748 vulnerability detected in CandidATS version 3.0.0 exposes the application to cross-site scripting (XSS) attacks. Specifically, an external attacker can exploit the 'sortDirection' parameter in the 'ajax.php' resource to steal the cookie of any user accessing the system. As CandidATS fails to properly validate user input against XSS attacks, an attacker can inject malicious code into the system and execute it as part of a crafted request, thereby gaining unauthorized access to sensitive data.

When exploited, the CVE-2022-42748 vulnerability can lead to severe consequences for users of CandidATS. Attackers can use stolen cookies to hijack user sessions, which may contain sensitive information such as login credentials, personal data, and private notes on job candidates. This puts user data at risk of theft and compromise, which can lead to reputation damage, legal repercussions, and financial loss.

At s4e.io, we provide a range of pro features that enable users to quickly and easily identify vulnerabilities in their digital assets. Our platform offers automated vulnerability scanning, risk assessment, and remediation guidance, all in one integrated solution. With s4e.io, you can be confident that your online presence is protected against the latest threats and vulnerabilities.

 

REFERENCES

Solution Advice

To protect against the CVE-2022-42748 vulnerability, users of CandidATS are advised to take the following precautions:

  • Update to the latest version of CandidATS
  • Implement input validation and sanitization checks on all user input
  • Use HTTPS to encrypt all data transmitted between users and the CandidATS server
  • Employ a web application firewall (WAF) to detect and block malicious requests
  • Educate users on the risks of XSS attacks and how to avoid them

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.