Medium severity4.3NVD Advisory· Published Nov 25, 2025· Updated Jun 17, 2026
CVE-2025-65647
CVE-2025-65647
Description
Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=2.1+ 2 more
- (no CPE)range: <=2.1
- (no CPE)
- cpe:2.3:a:phpgurukul:online_shopping_portal:2.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- github.com/SachuuZ/CVE/tree/main/CVE-2025-65647nvdExploitMitigationThird Party Advisory
- phpgurukul.comnvdProduct
News mentions
0No linked articles in our index yet.