CVE-2022-29008

MEDIUM

Bus Pass Management System v1.0 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2022-29008. PoCs published by sudoninja, sudoninja-noob.

AI-analyzed exploit summary This is a writeup describing an Insecure Direct Object Reference (IDOR) vulnerability in Bus Pass Management System 1.0. The 'viewid' parameter in the URL can be manipulated to access unauthorized data without proper authentication checks.

Description

An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.

Exploits (2)

exploitdb WRITEUP VERIFIED
by sudoninja · textwebappsphp
https://www.exploit-db.com/exploits/50263

This is a writeup describing an Insecure Direct Object Reference (IDOR) vulnerability in Bus Pass Management System 1.0. The 'viewid' parameter in the URL can be manipulated to access unauthorized data without proper authentication checks.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Bus Pass Management System 1.0
Auth required
Prerequisites: Access to the admin panel · Valid credentials for initial authentication
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec STUB
by sudoninja-noob · poc
https://github.com/sudoninja-noob/CVE-2022-29008

The repository contains only a README.md file with a CVE identifier and no functional exploit code or technical details. It appears to be a placeholder or incomplete submission.

Classification
Stub 10%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/50263

Scores

CVSS v3 6.5
EPSS 0.0124
EPSS Percentile 65.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-639
Status published
Products (1)
phpgurukul/bus_pass_management_system 1.0
Published May 11, 2022
Tracked Since Feb 18, 2026