PT-2026-93125 · Tts-Be · Tts-Be
CVE-2026-88065
·
Published
2026-09-15
·
Updated
2026-09-16
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
tts-be versions prior to 2.1.0
Description
Broken Access Control exists across several API endpoints, including '/api/student/{id}/photo' and '/api/course unit/{id}/exchange/metadata'. By chaining these unauthenticated endpoints, a remote attacker can utilize the backend as an open proxy to bypass authorization checks. This allows for the enumeration and extraction of sensitive Personally Identifiable Information (PII) from upstream university systems, including full names, student IDs, class schedules, and photos.
Recommendations
Update to version 2.1.0.
Restrict access to the '/api/student/{id}/photo' and '/api/course unit/{id}/exchange/metadata' endpoints to minimize the risk of exploitation.
Exploit
Fix
IDOR
Missing Authentication
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tts-Be