First published: Mon Mar 03 2025(Updated: )
Incorrect access control in the component /rest/staffResource/findAllUsersAcrossOrg of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Serosoft Academia Student Information System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27583 has a high severity rating due to incorrect access control allowing unauthorized account modifications.
To fix CVE-2025-27583, implement proper access controls in the /rest/staffResource/findAllUsersAcrossOrg endpoint.
CVE-2025-27583 affects Serosoft Solutions Pvt Ltd Academia Student Information System EagleR version 1.0.118.
Attackers can create and modify user accounts, including privileged Administrator accounts, due to this vulnerability.
As of now, it is recommended to monitor for vendor updates regarding a security patch for CVE-2025-27583.