Home

Description

An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records by modifying the 'rec_no' parameter in the /student/get-receipt endpoint.

PUBLISHED Reserved 2025-09-26 | Published 2025-12-04 | Updated 2025-12-04 | Assigner mitre

References

drive.google.com/...TY6KU4uaelAUn7L9Cn6XfjC/view?usp=sharing

medium.com/...acked-all-universities-in-my-city-d6b8e320455c

github.com/sharma19d/CVE-2025-61148

cve.org (CVE-2025-61148)

nvd.nist.gov (CVE-2025-61148)