{"id":"CVE-2025-8887","title":"Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Usta Information Systems Inc","summary":"Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Usta Information Systems Inc. Aybs Interaktif allows Forceful Browsing, Parameter Inject…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","cwe":["CWE-200","CWE-639","CWE-862"],"published":"2025-10-10","updated":"2026-10-08","sourceUpdated":"2026-10-08T13:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-8887","references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0329","label":"iletisim@usom.gov.tr"},{"url":"https://www.usom.gov.tr/bildirim/tr-25-0329","label":"iletisim@usom.gov.tr"}],"tags":["nvd"],"epss":0.00148,"epssPercentile":0.03521,"ingestedAt":"2026-10-08T13:42:55.084Z","slug":"CVE-2025-8887","body":"## Overview\n\nAuthorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Usta Information Systems Inc. Aybs Interaktif allows Forceful Browsing, Parameter Injection, Input Data Manipulation.\n\nThis issue affects Aybs Interaktif: from 2024 through 28082025.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}