CVE-2022-25095

CRITICAL

Home Owners Collection Management System v1.0 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-25095. PoCs published by Saud Alenazi.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated account takeover vulnerability in Home Owners Collection Management System 1.0. By sending a crafted POST request to the Users.php endpoint, an attacker can modify user account details, including username and password, without authentication.

Description

Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request.

Exploits (1)

exploitdb WORKING POC
by Saud Alenazi · textwebappsphp
https://www.exploit-db.com/exploits/50730

This exploit demonstrates an unauthenticated account takeover vulnerability in Home Owners Collection Management System 1.0. By sending a crafted POST request to the Users.php endpoint, an attacker can modify user account details, including username and password, without authentication.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Home Owners Collection Management System 1.0
No auth needed
Prerequisites: Access to the target application's endpoint · Knowledge of the target user's ID or ability to guess/iterate
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/50730

Scores

CVSS v3 9.8
EPSS 0.0132
EPSS Percentile 67.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
home_owners_collection_management_system_project/home_owners_collection_management_system 1.0
Published Feb 26, 2022
Tracked Since Feb 18, 2026