This issue affects Yaay Social Media App: from 3.8.0 through 24102025.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 14 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Media App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Yaay Social Media App: from 3.8.0 through 24102025. | |
| Title | IDOR in APPYAP's Yaay Social Media App | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TR-CERT
Published:
Updated: 2026-05-14T13:47:07.516Z
Reserved: 2025-10-21T08:47:55.324Z
Link: CVE-2025-12008
Updated: 2026-05-14T13:47:02.759Z
Status : Deferred
Published: 2026-05-14T13:16:16.133
Modified: 2026-05-14T16:20:13.477
Link: CVE-2025-12008
No data.
OpenCVE Enrichment
Updated: 2026-05-14T15:15:23Z