CVE-2025-65647 Overview
CVE-2025-65647 is an Insecure Direct Object Reference (IDOR) vulnerability in the Track Order function of PHPGurukul Online Shopping Portal 2.1. The flaw allows an authenticated user to disclose order information belonging to other users by manipulating the oid parameter. The weakness is classified as [CWE-639] Authorization Bypass Through User-Controlled Key.
The vulnerability requires low privileges and no user interaction over the network. It affects confidentiality only; integrity and availability are not impacted. EPSS data from the enriched record lists a probability of 0.244% with a percentile of 14.29.
Critical Impact
Authenticated attackers can enumerate the oid parameter in the Track Order function to view order details belonging to other customers of the portal.
Affected Products
- PHPGurukul Online Shopping Portal 2.1
- Deployments using the track-order function with the oid parameter
- CPE: cpe:2.3:a:phpgurukul:online_shopping_portal:2.1:*:*:*:*:*:*:*
Discovery Timeline
- 2025-11-25 - CVE-2025-65647 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-65647
Vulnerability Analysis
The Track Order feature in PHPGurukul Online Shopping Portal 2.1 accepts an order identifier through the oid query parameter. The application retrieves and renders order details based on this parameter without verifying that the authenticated session owns the referenced order. An authenticated user can substitute arbitrary values for oid and read records belonging to other customers.
The exposed data corresponds to order tracking information rendered by the Track Order view. Because order identifiers are typically sequential integers, enumeration across the full range of valid identifiers is straightforward for an attacker with a valid login.
Root Cause
The root cause is a missing object-level authorization check in the server-side handler for the Track Order function. The application trusts the user-supplied oid as the sole key for data lookup and does not cross-reference the current session's user identity against the owner of the order record. This matches the pattern described in [CWE-639].
Attack Vector
Exploitation requires authenticated access to the portal, which can be obtained through normal account registration. The attacker issues HTTP requests to the Track Order endpoint and iterates through values of the oid parameter. Each response that corresponds to a valid identifier returns order data for the associated customer. No code execution, elevation of privilege, or write access is produced; the impact is limited to confidentiality.
Additional technical details are available in the GitHub PoC repository referenced in the NVD entry.
Detection Methods for CVE-2025-65647
Indicators of Compromise
- Repeated requests to the Track Order endpoint from a single authenticated session with sequentially changing oid values.
- Access patterns where a single user account requests order identifiers that are not associated with that account's purchase history.
- Unusual volumes of HTTP 200 responses from the Track Order handler for one source IP within a short interval.
Detection Strategies
- Instrument the Track Order handler to log the authenticated user ID alongside the requested oid, then alert on mismatches between order owner and requester.
- Deploy web application firewall rules that flag high-rate parameter enumeration against the track-order endpoint.
- Correlate authentication logs with order lookup requests to identify accounts touching an abnormal number of distinct oid values.
Monitoring Recommendations
- Review historical access logs for the Track Order endpoint to identify prior enumeration against the oid parameter.
- Baseline normal order-lookup behavior per account and alert on deviations.
- Monitor the vendor site for a patched release or security advisory.
How to Mitigate CVE-2025-65647
Immediate Actions Required
- Restrict access to the Track Order function to authenticated sessions only, and enforce server-side checks that bind each oid to the owning account.
- If a patched release is unavailable, apply a reverse-proxy or application-layer control that validates ownership of the requested oid before the response is returned.
- Rotate exposed customer data notifications and review order records that may have been accessed by other accounts.
Patch Information
At the time of the NVD entry's last modification on 2026-06-17, no vendor-released patch is listed in the enriched data. Operators should monitor the PHP Gurukul site for an updated release of the Online Shopping Portal that addresses the Track Order authorization check.
Workarounds
- Replace numeric sequential order identifiers with unpredictable values such as UUIDs to raise the cost of enumeration while an authorization fix is prepared.
- Add a server-side middleware check that compares the session user ID against the owner of the requested order before rendering the Track Order view.
- Rate-limit requests to the Track Order endpoint per account and per source IP to slow enumeration attempts.
# Example nginx rule to rate-limit the track-order endpoint
limit_req_zone $binary_remote_addr zone=trackorder:10m rate=10r/m;
location /track-order.php {
limit_req zone=trackorder burst=5 nodelay;
proxy_pass http://backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.