Serosoft

Academia Student Information System

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.92%
  • Veröffentlicht 26.04.2025 00:00:00
  • Zuletzt bearbeitet 29.01.2026 17:57:58

An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.

  • EPSS 0.11%
  • Veröffentlicht 03.03.2025 01:15:12
  • Zuletzt bearbeitet 27.06.2025 13:43:45

Incorrect access control in the component /rest/staffResource/findAllUsersAcrossOrg of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.

  • EPSS 0.06%
  • Veröffentlicht 03.03.2025 01:15:12
  • Zuletzt bearbeitet 27.06.2025 13:43:35

A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the First Name pa...

  • EPSS 0.06%
  • Veröffentlicht 03.03.2025 01:15:12
  • Zuletzt bearbeitet 27.06.2025 13:23:31

A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Print Name pa...

  • EPSS 0.1%
  • Veröffentlicht 03.03.2025 01:15:11
  • Zuletzt bearbeitet 12.12.2025 16:15:43

Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.

  • EPSS 0.15%
  • Veröffentlicht 03.03.2025 01:15:11
  • Zuletzt bearbeitet 12.12.2025 16:15:43

An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information.

  • EPSS 0.1%
  • Veröffentlicht 03.03.2025 01:15:11
  • Zuletzt bearbeitet 12.12.2025 16:15:43

An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information via a cr...

  • EPSS 0.11%
  • Veröffentlicht 03.03.2025 01:15:11
  • Zuletzt bearbeitet 12.12.2025 16:15:44

Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. This vulnerability allows authenticated attackers to escalate privileges and access sensitive informati...