CVE-2025-61148
MEDIUMedupluscampus 3.0.1 - Authenticated Insecure Direct Object Reference via 'rec_no' Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-61148. PoCs published by sharma19d.
AI-analyzed exploit summary This repository contains a detailed writeup for CVE-2025-61148, an IDOR vulnerability in the EduplusCampus Student Payment API. It describes how an attacker can exploit the lack of authorization checks to access other users' receipts by manipulating the `rec_no` parameter.
Description
An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment API allows authenticated users to access other students personal and financial records by modifying the 'rec_no' parameter in the /student/get-receipt endpoint.
Exploits (1)
This repository contains a detailed writeup for CVE-2025-61148, an IDOR vulnerability in the EduplusCampus Student Payment API. It describes how an attacker can exploit the lack of authorization checks to access other users' receipts by manipulating the `rec_no` parameter.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N