CVE-2025-8887

MEDIUM

Usta Information Systems Inc. Aybs Interaktif - Info Disclosure

Title source: llm
STIX 2.1

Description

Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Usta Information Systems Inc. Aybs Interaktif allows Forceful Browsing, Parameter Injection, Input Data Manipulation.This issue affects Aybs Interaktif: from 2024 through 28082025.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource
https://www.usom.gov.tr/bildirim/tr-25-0329

Scores

CVSS v3 6.1
EPSS 0.0001
EPSS Percentile 3.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-639 CWE-862
Status published
Products (1)
Usta Information Systems Inc./Aybs Interaktif 2024 - 28082025
Published Oct 10, 2025
Tracked Since Feb 18, 2026