Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-31295. PoCs published by bigzooooz.
AI-analyzed exploit summary This PoC demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Online Discussion Forum Site 1.0, allowing unauthorized deletion of posts by manipulating the 'id' parameter in a form submission. The exploit targets the 'delete_post' function in the specified PHP file.
Description
An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts.
Exploits (1)
This PoC demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Online Discussion Forum Site 1.0, allowing unauthorized deletion of posts by manipulating the 'id' parameter in a form submission. The exploit targets the 'delete_post' function in the specified PHP file.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N