CVE-2025-40650

HIGH

Clickedu - Info Disclosure

Title source: llm
STIX 2.1

Description

Insecure Direct Object Reference (IDOR) vulnerability in Clickedu. This vulnerability could allow an attacker to retrieve information about student report cards.

Scores

CVSS v4 8.7
EPSS 0.0032
EPSS Percentile 55.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
Clickedu/Clickedu all versions
Published May 26, 2025
Tracked Since Feb 18, 2026