PT-2025-9244 · Serosoft Solutions Pvt · Academia Student Information System (Sis) Eagler

Published

2025-03-03

·

Updated

2025-03-08

·

CVE-2025-27583

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR version 1.0.118
Description The issue is related to incorrect access control in the component "/rest/staffResource/findAllUsersAcrossOrg" of the affected software, allowing unauthorized creation and modification of user accounts, including an Administrator account.
Recommendations For version 1.0.118, consider restricting access to the /rest/staffResource/findAllUsersAcrossOrg endpoint until a fix is available. Additionally, review and limit user account creation and modification privileges to authorized personnel only.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27583

Affected Products

Academia Student Information System (Sis) Eagler