PT-2025-38404 · Unknown · Youth-Is-As-Pale-As-Poetry E-Learning

Chen_Yun_N

·

Published

2025-09-18

·

Updated

2025-09-18

·

CVE-2025-10671

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions youth-is-as-pale-as-poetry e-learning version 1.0
Description A vulnerability exists due to insufficiently random values generated by the encryptSecret function within the JWT Token Handler component. The vulnerable file is e-learning-masterexam-apisrcmainjavacomyfexamabilityshirojwtJwtUtils.java. The issue is remotely exploitable, but requires a high level of complexity and is considered difficult to exploit. The exploit has been publicly disclosed.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of the encryptSecret function until a patch is available.

Exploit

Fix

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2025-10671

Affected Products

Youth-Is-As-Pale-As-Poetry E-Learning