First published: Mon Mar 03 2025(Updated: )
A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the User ID parameter at /rest/staffResource/update.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Serosoft Academia Student Information System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25949 is categorized as a stored cross-site scripting (XSS) vulnerability with a high severity due to its potential impact on user data and application integrity.
CVE-2025-25949 exploits the Academia SIS EagleR application by allowing attackers to inject a crafted payload into the User ID parameter, executing arbitrary web scripts or HTML.
To fix CVE-2025-25949, sanitize and validate user inputs to ensure that no malicious scripts can be injected into the User ID parameter.
CVE-2025-25949 affects users of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118.
Exploitation of CVE-2025-25949 can lead to data theft, session hijacking, or unauthorized actions on behalf of users within the affected application.