An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/50263 | exploit vdb entry third party advisory |
https://github.com/sudoninja-noob/CVE-2022-29008/blob/main/CVE-2022-29008.txt | third party advisory |