Home

Description

Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bus Ticket Booking with Seat Reservation: from n/a before 5.6.8.

PUBLISHED Reserved 2025-11-21 | Published 2026-05-07 | Updated 2026-05-07 | Assigner Patchstack




MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-862 Missing Authorization

Product status

Default status
unaffected

Any version before 5.6.8
affected

Credits

Legion Hunter | Patchstack Bug Bounty program finder

References

patchstack.com/...ken-access-control-vulnerability?_s_id=cve vdb-entry

cve.org (CVE-2025-66105)

nvd.nist.gov (CVE-2025-66105)

Download JSON