S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-42749 Scanner

CVE-2022-42749 scanner - Cross-Site Scripting (XSS) vulnerability in CandidATS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-42749
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitrary users. This is possible because the application application does not properly validate user input against XSS attacks.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
CandidATSby n/a
3.0.0
Updated Aug 22, 2026View on NVD →
Detail

CandidATS is an open-source Applicant Tracking System (ATS) that allows recruiters to manage the entire candidate lifecycle, from job postings and resumes to candidate communication and hiring. Designed to simplify and streamline recruitment processes, CandidATS is used by organizations of all sizes to identify potential employees and manage applications.

Recently, a serious vulnerability was identified in CandidATS that has been labeled CVE-2022-42749. The vulnerability is located in the 'page' of the 'ajax.php' resource and enables an external attacker to steal the cookie of any user. The application is vulnerable because it lacks proper validation for user input, leaving it susceptible to cross-site scripting (XSS) attacks.

Exploiting this vulnerability can lead to serious consequences. Once an attacker has gained access to user cookies, they can take over the account, access sensitive information, and perform unauthorized actions. This could include anything from downloading confidential files to altering job postings, leading to serious harm for the victim organization and its employees.

At s4e.io, we are committed to helping individuals and organizations protect their digital assets from harm. With our pro features, you can easily and quickly learn about vulnerabilities that may exist in your digital infrastructure. By staying informed and taking proactive measures to prevent attacks, you can safeguard your sensitive information and ensure the security of your operations.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken, including:

  • Implementing regular security updates to the software
  • Disabling the use of cookies or session identifiers where possible
  • Configuring firewall and intrusion prevention settings to prevent exploit attempts
  • Educating users on proper security practices, such as using strong passwords and enabling two-factor authentication
  • Enlisting the help of a third-party security audit to identify and resolve vulnerabilities before they can be exploited.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-42749 scanner - Cross-Site Scripting (XSS) vulnerability in CandidATS | S4E