CVE-2022-42989
Critical · CVSS 9.0ERP Sankhya — Cross-Site Scripting (XSS)
- CVSS
- 9.0
- nvd
- EPSS
- 1.01%
- 59th pct
- KEV
- No
- Class
- other
- CWE-79, CWE-79
Description
ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.
Search profile — drives PoC discovery
Symbols Caixa de EntradaSankhyaERP_XSS_Account_Takeover0xLUC4S
Keywords CVE-2022-42989Sankhya ERPXSSCaixa de Entradacross-site scriptingaccount takeoverSankhyaERPv4.11b81
Versions: before v4.11b81
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z