Skip to content

Instantly share code, notes, and snippets.

View Voidager88's full-sized avatar

Voidager88

View GitHub Profile
@Voidager88
Voidager88 / PoC_CVE-2022-29950
Last active June 6, 2022 07:30
*** (Revoking Request) *** PoC of Modification of Assumed-Immutable Data (MAID) vulnerability in Experian Hunter 1.16 via (1) rule name parameter to the Rules page or the (2) subrule name or (3) categories name parameter to the Subrules page (CVE-2022-29950)
*** Revoking Request ***
[Product Description]
Experian Hunter is ideal to prevent application fraud for any organisation that deals with application fraud data across multiple channels.
[Details]
The current Rules and Subrules pages were vulnerable to Modification of Assumed-Immutable Data (MAID) vulnerability. The application does not properly protect assumed-immutable information, such as names and categories of existing Rules and Subrules, from being modified. By default, The application does not allow user to modify the names or categories of existing Rules and Subrules. It only allows user to change the description and criteria of Rules and Subrules.
[Impact]
The successful exploitation of this vulnerability may result in the addition or modification of data. If the data is tampered with, it becomes untrustworthy. The manipulated data may provide unexpected results when the data is processed.