CVE-2025-25777
PoC —CVSS 3.1
8.0 high
EPSS
<1%p17
Published
()
Modified
Description
Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.
- Vendors
- codeastro
- Products
- bus ticket booking system
- Weakness
- CWE-639
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.