ZeroHour

CVE-2025-61148

PoC ×2
CVSS 3.1
6.5 medium
EPSS
<1%p28
Published
()
Modified
Description

An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records by modifying the 'rec_no' parameter in the /student/get-receipt endpoint.

Vendors
edupluscampus
Products
edupluscampus
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.