PT-2025-31656 · Unknown · Institute-Of-Current-Students
Pronay Biswas
·
Publicado
2025-08-01
·
Atualizado
2025-08-01
·
CVE-2025-50870
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Institute-of-Current-Students version 1.0
Description
The software is susceptible to Incorrect Access Control. The
mydetailsstudent.php endpoint allows unauthorized access to student details. The myds GET parameter accepts an email address as input and directly returns the corresponding student's personal information without proper identity or permission validation. This enables an attacker to enumerate and retrieve sensitive student details by manipulating the email value in the request URL, resulting in information disclosure.Recommendations
Ensure proper validation of user identity and permissions before accessing or disclosing student information through the
mydetailsstudent.php endpoint.
Restrict access to the myds GET parameter to authorized users only.Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Institute-Of-Current-Students