CVE-2025-56392: Syauqi Collegetivity

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attackers to impersonate other users and perform arbitrary operations via a crafted POST request.

Affected products

  • Syauqi Collegetivity: version 1.0.0 only

Published 2025-09-30. Last modified 2026-06-17.