Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fp99-3rpw-vrxx

Опубликовано: 04 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records by modifying the 'rec_no' parameter in the /student/get-receipt endpoint.

An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records by modifying the 'rec_no' parameter in the /student/get-receipt endpoint.

EPSS

Процентиль: 10%
0.00034
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
nvd
2 месяца назад

An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records by modifying the 'rec_no' parameter in the /student/get-receipt endpoint.

EPSS

Процентиль: 10%
0.00034
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639