CVE-2025-25777HIGH 8.0EPSS p14.0%
CVE-2025-25777CVE-2025-25777
Description
Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.
Scoring
| CVSS 3.1 | 8.0 (HIGH) |
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
| EPSS | 0.23% probability of exploitation · percentile 14.0% · 2026-06-18T12:00:27Z |
| Published | 2025-04-24 |
| Last modified | 2025-05-28 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Authorization Bypass Through User-Controlled Keycwe-639 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.