Incorrect access control in the component /rest/staffResource/findAllUsersAcrossOrg of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.
References
Configurations
No configuration.
History
05 Mar 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
Summary |
|
|
CWE | CWE-862 |
03 Mar 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-03 01:15
Updated : 2025-03-05 17:15
NVD link : CVE-2025-27583
Mitre link : CVE-2025-27583
CVE.ORG link : CVE-2025-27583
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization