PT-2022-19930 · Experian · Experian Hunter

Voidager88

·

Published

2022-05-04

·

Updated

2024-08-03

·

CVE-2022-29950

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Experian Hunter version 1.16
Description The issue allows remote authenticated users to modify assumed-immutable elements. This can be achieved via the rule name parameter to the "Rules page" or the subrule name or categories name parameter to the "Subrules page". The vendor disputes this issue because version 1.16 has never existed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2022-29950

Affected Products

Experian Hunter