CVE-2025-56392: Syauqi Collegetivity
High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.
An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attackers to impersonate other users and perform arbitrary operations via a crafted POST request.
Affected products
- Syauqi Collegetivity: version 1.0.0 only
Published 2025-09-30. Last modified 2026-06-17.