Vulnerabilities (CVE)

Filtered by vendor Edupluscampus Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-61148 1 Edupluscampus 1 Edupluscampus 2025-12-16 N/A 6.5 MEDIUM
An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records by modifying the 'rec_no' parameter in the /student/get-receipt endpoint.