#VU63989 Authorization bypass through user-controlled key in Bus Pass Management System - CVE-2022-29008

 

#VU63989 Authorization bypass through user-controlled key in Bus Pass Management System - CVE-2022-29008

Published: June 6, 2022


Vulnerability identifier: #VU63989
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2022-29008
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Bus Pass Management System
Software vendor:
PHPGurukul

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to missing authorization checks in /buspassms/admin/view-pass-detail.php script. A remote attacker can obtain sensitive information by manipulating the value of the "viewid" HTTP GET parameter.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links