PT-2025-49097 · Unknown · Edupluscampus
Published
2025-12-04
·
Updated
2025-12-06
·
CVE-2025-61148
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
EduplusCampus version 3.0.1
Description
An Insecure Direct Object Reference (IDOR) exists in the Student Payment API. Authenticated users can access other students’ personal and financial records by manipulating the
rec no parameter within the /student/get-receipt API endpoint.Recommendations
Restrict access to the
/student/get-receipt API endpoint to authorized users only.
Implement proper authorization checks to ensure users can only access their own records.
Sanitize and validate the rec no parameter to prevent manipulation.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edupluscampus