PT-2025-45577 · Yungifez · Skuul School Management System

Zeeshan Khan

·

Published

2025-11-09

·

Updated

2025-12-11

·

CVE-2025-12918

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions yungifez Skuul School Management System versions up to 2.6.5
Description A security flaw exists in yungifez Skuul School Management System. Manipulation of the invoice id argument within an unknown function of the /dashboard/fees/fee-invoices/ file, part of the View Fee Invoice component, leads to improper control of resource identifiers. Remote exploitation is possible, and the exploit has been publicly released. The complexity of the attack is considered high, and exploitability is difficult. The vendor was contacted but did not respond.
Recommendations Versions prior to 2.6.5 should be used.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-12918
GHSA-FQQ7-H225-8W6H

Affected Products

Skuul School Management System