VulnerabilityAnalyzed
CVE-2025-61148
An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records by modifying the 'rec_no' parameter in the /student/get-receipt…
MEDIUM 6.5EPSS 0.35%
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records by modifying the 'rec_no' parameter in the /student/get-receipt endpoint.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-639
- Affected
- edupluscampus/edupluscampus
- Source
- cve@mitre.org
References
- https://drive.google.com/file/d/1BRZRurbl7TY6KU4uaelAUn7L9Cn6XfjC/view?usp=sharingExploit, Third Party Advisory
- https://github.com/sharma19d/CVE-2025-61148Exploit, Third Party Advisory
- https://medium.com/@Charon19d/how-i-hacked-all-universities-in-my-city-d6b8e320455cProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.