MEDIUM
CVE-2025-15657
CVSS
5.3
Description
Unauthenticated Insecure Direct Object References (IDOR) in School Management <= 93.1.0 versions.
Summary dbcve.org
Unauthenticated IDOR vulnerability in School Management <= 93.1.0 allows unauthenticated attackers to directly reference object identifiers (e.g., database records, files) to access or modify sensitive data without proper authorization validation.
Mitigation
Implement proper object-level authorization checks on all sensitive endpoints and validate user permissions before allowing access to, or modification of, any object references.
Weakness (CWE)
CWE-639
Authorization Bypass (IDOR)
EPSS Score
0.22%
Probability of exploitation in next 30 days
12.9th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.