PT-2025-38658 · Unknown · Academico-Sis

Khanmarshal

·

Published

2025-09-21

·

Updated

2025-09-21

·

CVE-2025-10763

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions academico-sis versions prior to d9a9e2636fbf7e5845ee086bcb03ca62faceb6ab
Description A vulnerability exists in academico-sis related to the Profile Picture Handler component. The issue involves unrestricted upload via the /edit-photo file. This manipulation is possible to be carried out remotely. The exploit has been publicly disclosed. The product adopts a rolling release strategy to maintain continuous delivery.
Recommendations Update academico-sis to version d9a9e2636fbf7e5845ee086bcb03ca62faceb6ab or later.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-10763

Affected Products

Academico-Sis