First published: Mon Apr 21 2025(Updated: )
A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects unknown code of the file /api/studentPWD. The manipulation of the argument studentId leads to unverified password change. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
YXJ2018 SpringBoot-Vue-OnlineExam |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3849 is classified as a problematic vulnerability due to the potential for unverified password changes.
To fix CVE-2025-3849, implement proper authentication mechanisms to verify password changes associated with the studentId.
The risks associated with CVE-2025-3849 include unauthorized access and security breaches due to unverified password changes.
CVE-2025-3849 affects users of the YXJ2018 SpringBoot-Vue-OnlineExam version 1.0 software.
Yes, CVE-2025-3849 can be exploited remotely, allowing attackers to manipulate password changes without proper verification.