Unauthenticated Access Control Vulnerability in HMS v1.0 Allows Unauthorized PHP File Access and Modification

Unauthenticated Access Control Vulnerability in HMS v1.0 Allows Unauthorized PHP File Access and Modification

CVE-2022-25402 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.

Learn more about our Web Application Penetration Testing UK.