CodeAstro Bus Ticket Booking System 1.0

CPE Details

CodeAstro Bus Ticket Booking System 1.0
1.0
2025-05-02
17h38 +00:00
2025-05-02
17h38 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:codeastro:bus_ticket_booking_system:1.0:*:*:*:*:*:*:*

Informations

Vendor

codeastro

Product

bus_ticket_booking_system

Version

1.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-25776 2025-04-28 00h00 +00:00 Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing.
5
Medium
CVE-2025-25775 2025-04-25 00h00 +00:00 Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.
9.8
Critical
CVE-2025-25777 2025-04-24 00h00 +00:00 Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.
8
High