CVE-2025-25777

Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:codeastro:bus_ticket_booking_system:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-24 21:15

Updated : 2025-05-28 13:41


NVD link : CVE-2025-25777

Mitre link : CVE-2025-25777

CVE.ORG link : CVE-2025-25777


JSON object : View

Products Affected

codeastro

  • bus_ticket_booking_system
CWE
CWE-639

Authorization Bypass Through User-Controlled Key