CVE-2022-25095
CRITICALHome Owners Collection Management System v1.0 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-25095. PoCs published by Saud Alenazi.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated account takeover vulnerability in Home Owners Collection Management System 1.0. By sending a crafted POST request to the Users.php endpoint, an attacker can modify user account details, including username and password, without authentication.
Description
Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request.
Exploits (1)
This exploit demonstrates an unauthenticated account takeover vulnerability in Home Owners Collection Management System 1.0. By sending a crafted POST request to the Users.php endpoint, an attacker can modify user account details, including username and password, without authentication.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H