First published: Mon Mar 03 2025(Updated: )
A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Print Name parameter at /rest/staffResource/update.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Serosoft Academia Student Information System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-27585 is classified as high due to its potential for arbitrary code execution through stored XSS.
To fix CVE-2025-27585, ensure proper input validation and output encoding for the Print Name parameter in the application.
CVE-2025-27585 affects version 1.0.118 of the Serosoft Solutions Academia Student Information System (SIS) EagleR.
Yes, CVE-2025-27585 can potentially lead to data theft as attackers can execute arbitrary web scripts.
As of now, specific exploits for CVE-2025-27585 have not been publicly documented, but the vulnerability's nature poses significant risk.