CVE 8.8 HIGH

IDOR in APPYAP’s Yaay Social Media App_CVE-2025-12008

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Media App allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Yaay Social Media App: from 3.8.0 through 24102025.

AI Analysis

Authorization bypass vulnerability in Yaay Social Media App due to improper ACL constraints

Basic Information

ID CVE-2025-12008
Source TR-CERT
Published May 14, 2026 at 12:31
Modified May 14, 2026 at 13:47

Affected Product

Vendor APPYAP Technology and Information Inc.
Product Yaay Social Media App
Version 3.8.0
Affected Versions APPYAP Technology and Information Inc. Yaay Social Media App 3.8.0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor APPYAP Technology and Information Inc.
Product Yaay Social Media App
Version 3.8.0-24102025

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.