8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Media App allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Yaay Social Media App: from 3.8.0 through 24102025.
This issue affects Yaay Social Media App: from 3.8.0 through 24102025.
AI Analysis
Authorization bypass vulnerability in Yaay Social Media App due to improper ACL constraints
Basic Information
ID
CVE-2025-12008
Source
TR-CERT
Published
May 14, 2026 at 12:31
Modified
May 14, 2026 at 13:47
Affected Product
Vendor
APPYAP Technology and Information Inc.
Product
Yaay Social Media App
Version
3.8.0
Affected Versions
APPYAP Technology and Information Inc. Yaay Social Media App 3.8.0
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
APPYAP Technology and Information Inc.
Product
Yaay Social Media App
Version
3.8.0-24102025