CVE-2025-31338

MEDIUM

Wisdom Master Pro <5.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

A missing authorization vulnerability in the retrieve teacher Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to obtain partial user data by accessing the API functionality.

References (1)

Core 1
Core References
Vendor Advisory third-party-advisory
https://zuso.ai/advisory/za-2025-01

Scores

CVSS v4 6.9
EPSS 0.0037
EPSS Percentile 29.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
SUNNET Technology Co., Ltd./Wisdom Master Pro 5.0 - 5.2
Published Apr 17, 2025
Tracked Since Feb 18, 2026