PT-2025-9242 · Serosoft Solutions Pvt · Academia Student Information System (Sis) Eagler

Ralph El Khoury

·

Published

2025-03-03

·

Updated

2025-12-12

·

CVE-2025-25952

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR version 1.0.118
Description The issue is related to an Insecure Direct Object References (IDOR) in the component "/getStudemtAllDetailsById?studentId=XX". This allows attackers to access sensitive user information via a crafted API request.
Recommendations For version 1.0.118, as a temporary workaround, consider restricting access to the "/getStudemtAllDetailsById?studentId=XX" API endpoint until a patch is available. Avoid using the studentId variable in the affected API endpoint until the issue is resolved.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-25952

Affected Products

Academia Student Information System (Sis) Eagler