CVE-2025-25777: High severity codeastro bus ticket booking system vulnerability
Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25777?
CVE-2025-25777 has a high severity rating due to the potential for unauthorized access to user profiles.
How do I fix CVE-2025-25777?
To fix CVE-2025-25777, implement proper authentication and authorization checks before accessing user profiles.
Who is affected by CVE-2025-25777?
The vulnerability CVE-2025-25777 affects users of Codeastro Bus Ticket Booking System v1.0.
What type of flaw is CVE-2025-25777?
CVE-2025-25777 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
What can attackers do with CVE-2025-25777?
Attackers can exploit CVE-2025-25777 to view other users' profiles by manipulating the URL user ID.