CVE-2025-50870
Last modified
CVE-2025-50870 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Institute-of-Current-Students 1.0 is vulnerable to Incorrect Access Control in the mydetailsstudent.php endpoint. The myds GET parameter accepts an email address as input and directly returns the corresponding student's personal information without validating the identity or permissions of the requesting user. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Institute-of-Current-Students 1.0 is vulnerable to Incorrect Access Control in the mydetailsstudent.php endpoint. The myds GET parameter accepts an email address as input and directly returns the corresponding student's personal information without validating the identity or permissions of the requesting user. This allows any authenticated or unauthenticated attacker to enumerate and retrieve sensitive student details by altering the email value in the request URL, leading to information disclosure.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-50870?
How severe is CVE-2025-50870?
How do I fix CVE-2025-50870?
Are you affected by CVE-2025-50870?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
