Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.
Metrics
Affected Vendors & Products
References
History
Wed, 28 May 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Codeastro
Codeastro bus Ticket Booking System |
|
CPEs | cpe:2.3:a:codeastro:bus_ticket_booking_system:1.0:*:*:*:*:*:*:* | |
Vendors & Products |
Codeastro
Codeastro bus Ticket Booking System |
Fri, 25 Apr 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-639 | |
Metrics |
cvssV3_1
|
Thu, 24 Apr 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-04-24T00:00:00.000Z
Updated: 2025-04-25T17:07:04.062Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25777

Updated: 2025-04-25T17:06:58.493Z

Status : Analyzed
Published: 2025-04-24T21:15:23.933
Modified: 2025-05-28T13:41:40.903
Link: CVE-2025-25777

No data.