An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records by modifying the 'rec_no' parameter in the /student/get-receipt endpoint.
History

Fri, 05 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Edupluscampus
Edupluscampus student Payment Api
Vendors & Products Edupluscampus
Edupluscampus student Payment Api

Thu, 04 Dec 2025 16:00:00 +0000

Type Values Removed Values Added
Description An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records by modifying the 'rec_no' parameter in the /student/get-receipt endpoint.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-12-04T00:00:00.000Z

Updated: 2025-12-04T15:48:52.203Z

Reserved: 2025-09-26T00:00:00.000Z

Link: CVE-2025-61148

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-04T16:16:22.107

Modified: 2025-12-04T17:15:08.283

Link: CVE-2025-61148

cve-icon Redhat

No data.