PT-2025-9240 · Serosoft Solutions Pvt · Academia Student Information System (Sis) Eagler

Ralph El Khoury

·

Published

2025-03-03

·

Updated

2025-12-12

·

CVE-2025-25950

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR version 1.0.118
Description The issue is related to incorrect access control in the component "/rest/staffResource/update" of the affected software, allowing unauthorized creation and modification of user accounts, including an Administrator account.
Recommendations For version 1.0.118, as a temporary workaround, consider restricting access to the "/rest/staffResource/update" API endpoint until a patch is available. Additionally, limit the ability to create and modify user accounts to authorized personnel only.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-25950

Affected Products

Academia Student Information System (Sis) Eagler