PT-2025-43998 · Unknown · Educare Erp
Published
2025-10-27
·
Updated
2025-10-27
·
CVE-2025-60982
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Educare ERP version 1.0
Description
An IDOR (Insecure Direct Object Reference) vulnerability exists that allows unauthorized access to sensitive data through manipulated object references. Affected API endpoints do not enforce proper authorization checks, enabling authenticated users to access or modify data belonging to other users by altering object identifiers in API requests. Attackers can exploit this flaw to view or modify sensitive records without appropriate authorization.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Educare Erp