CVE-2025-60982
MEDIUMEducare ERP 1.0 - Authenticated Insecure Direct Object Reference
Title source: llmDescription
IDOR vulnerability in Educare ERP 1.0 (2025-04-22) allows unauthorized access to sensitive data via manipulated object references. Affected endpoints do not enforce proper authorization checks, allowing authenticated users to access or modify data belonging to other users by changing object identifiers in API requests. Attackers can exploit this flaw to view or modify sensitive records without proper authorization.
References (2)
Core 2
Core References
Various Sources
https://www.educare.school/
Scores
CVSS v3
5.4
EPSS
0.0015
EPSS Percentile
4.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-284
Status
published
Published
Oct 27, 2025
Tracked Since
Feb 18, 2026