Experian Hunter 1.16 allows remote authenticated users to modify assumed-immutable elements via the (1) rule name parameter to the Rules page or the (2) subrule name or (3) categories name parameter to the Subrules page. NOTE: the vendor disputes this because version 1.16 has never existed
References
Link Resource
https://gist.github.com/Voidager88/73c2d512a72cceb0ef84dbf87a497d10 Exploit Third Party Advisory
https://www.experian.in/hunter Product Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-05-04T14:23:43

Updated: 2022-05-18T07:02:43

Reserved: 2022-04-29T00:00:00


Link: CVE-2022-29950

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-05-04T15:15:13.180

Modified: 2024-05-17T02:08:28.450


Link: CVE-2022-29950

JSON object: View

cve-icon Redhat Information

No data.