CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-42989

Critical · CVSS 9.0

ERP Sankhya — Cross-Site Scripting (XSS)

CVSS
9.0
nvd
EPSS
1.01%
59th pct
KEV
No
Class
other
CWE-79, CWE-79

Description

ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.

Search profile — drives PoC discovery

Symbols Caixa de EntradaSankhyaERP_XSS_Account_Takeover0xLUC4S
Keywords CVE-2022-42989Sankhya ERPXSSCaixa de Entradacross-site scriptingaccount takeoverSankhyaERPv4.11b81
Versions: before v4.11b81

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z