PT-2022-19930 · Experian · Experian Hunter

·

CVE-2022-29950

·

Published

2022-05-04

·

Updated

2024-08-03

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Experian Hunter version 1.16
Description The issue allows remote authenticated users to modify assumed-immutable elements. This can be achieved via the rule name parameter to the "Rules page" or the subrule name or categories name parameter to the "Subrules page". The vendor disputes this issue because version 1.16 has never existed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-29950

Affected Products

Experian Hunter