CVE-2025-48373

CRITICAL

Schule School Management System - Incorrect Authorization via Client-Side Role Manipulation

Title source: llm
STIX 2.1

Description

Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to redirect users to different panels based on their role. Prior to version 1.0.1, this implementation poses a serious security risk because it assumes that the value of data.role is trustworthy on the client side. Attackers can manipulate JavaScript in the browser (e.g., via browser dev tools or intercepting API responses) and set data.role to any arbitrary value (e.g., "admin"), gaining unauthorized access to restricted areas of the application.

Scores

CVSS v3 9.1
EPSS 0.0033
EPSS Percentile 25.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
schule111/schule_school_management_system 1.0.0
Published May 22, 2025
Tracked Since Feb 18, 2026