9.1
CVE-2025-25948
- EPSS 0.24%
- Veröffentlicht 03.03.2025 01:15:11
- Zuletzt bearbeitet 29.01.2026 02:05:39
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Academiaerp ≫ Student Information System Versioneagler-1.0.118
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.473 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.