CVE-2025-25777HIGH 8.0EPSS p17.3%
CVE-2025-25777CVE-2025-25777
Description
Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.
Scoring
| CVSS 3.1 | 8.0 (HIGH) |
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
| EPSS | 0.26% probability of exploitation · percentile 17.3% · 2026-08-03T12:00:16Z |
| Published | 2025-04-24 |
| Last modified | 2025-05-28 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Authorization Bypass Through User-Controlled Keycwe-639 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.