CVE-2025-1144

CRITICAL

School Affairs System - Info Disclosure

Title source: llm
STIX 2.1

Description

School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view specific pages and obtain database information as well as plaintext administrator credentials.

References (2)

Core 2
Core References
Various Sources third-party-advisory
https://www.twcert.org.tw/tw/cp-132-8415-853e0-1.html
Various Sources third-party-advisory
https://www.twcert.org.tw/en/cp-139-8416-b6cba-2.html

Scores

CVSS v3 9.8
EPSS 0.0047
EPSS Percentile 36.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-497
Status published
Products (1)
Quanxun/School Affairs System
Published Feb 11, 2025
Tracked Since Feb 18, 2026