Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.
References
Configurations
No configuration.
History
25 Apr 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE | CWE-639 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.0 |
24 Apr 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-24 21:15
Updated : 2025-04-29 13:52
NVD link : CVE-2025-25777
Mitre link : CVE-2025-25777
CVE.ORG link : CVE-2025-25777
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key