CodeAstro Bus Ticket Booking System 1.0

CPE Details

CodeAstro Bus Ticket Booking System 1.0
1.0
2025-05-02
17h38 +00:00
2025-05-02
17h38 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:codeastro:bus_ticket_booking_system:1.0:*:*:*:*:*:*:*

Informations

Vendor

codeastro

Product

bus_ticket_booking_system

Version

1.0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2025-25776 2025-04-28 00h00 +00:00 Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Ticket Booking System v1.0 allows an attacker to execute arbitrary code into the Full Name and Address fields during user registration or profile editing.
5
Moyen
CVE-2025-25775 2025-04-25 00h00 +00:00 Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.
9.8
Critique
CVE-2025-25777 2025-04-24 00h00 +00:00 Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.
8
Haute