Vulnerabilities
Vulnerable Software
Salonerp Project:  Security Vulnerabilities
SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the application does not correctly validate the page parameter against XSS attacks.
CVSS Score
6.1
EPSS Score
0.001
Published
2022-11-03
In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password.
CVSS Score
8.8
EPSS Score
0.009
Published
2022-01-14


Contact Us

Shodan ® - All rights reserved