First published: Mon Mar 03 2025(Updated: )
An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to access sensitive user information via a crafted API request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Serosoft Academia Student Information System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25952 is rated as a medium severity vulnerability due to its potential exposure of sensitive user information.
CVE-2025-25952 exploits Insecure Direct Object References (IDOR) to allow unauthorized access to sensitive user information.
Users of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 are affected by CVE-2025-25952.
To fix CVE-2025-25952, implement proper authorization checks for the API endpoint /getStudemtAllDetailsById?studentId=XX.
CVE-2025-25952 allows attackers to access sensitive user information through crafted API requests.