Junglewise Threat Intelligence

CVE-2025-8887: Usta Information Systems Aybs Interaktif authorization bypass

CVE-2025-8887 · Severity: medium · CVSS 6.1 · Published 2025-10-10

Executive brief

Usta Information Systems Aybs Interaktif, a management information system, contains a security flaw that allows unauthorized users to access sensitive data. By manipulating specific input parameters or browsing directly to restricted areas, an attacker can bypass security checks to view or modify information they should not have access to. This could lead to the exposure of confidential organizational data or unauthorized changes to system records.

Technical details

Aybs Interaktif by Usta Information Systems Inc. is vulnerable to multiple authorization-related issues, including CWE-639 (Authorization Bypass Through User-Controlled Key), CWE-862 (Missing Authorization), and CWE-200 (Exposure of Sensitive Information). The vulnerability allows for forceful browsing, parameter injection, and input data manipulation. An attacker with local access and low privileges can exploit these weaknesses to bypass intended access controls and interact with data belonging to other users or the system. The CVSS 3.1 base score is 6.1, reflecting high confidentiality impact but limited integrity impact and no availability impact. The issue affects versions from 2024 through August 28, 2025.

Affected products

  • Usta Information Systems Inc. Aybs Interaktif 2024 through 28082025

Timeline

  • 2025-10-10: advisory: Initial publication of the vulnerability advisory.

References

Related threats