Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-65681. PoCs published by Rivek619.
AI-analyzed exploit summary This repository contains a writeup for CVE-2025-65681, detailing an information disclosure vulnerability in Overhang.IO (tutor-open-edx) version 20.0.2. The issue arises due to improper cache-control headers and client-side session handling, allowing unauthorized access to sensitive information via browser back button navigation post-logout.
Description
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks.
Exploits (1)
This repository contains a writeup for CVE-2025-65681, detailing an information disclosure vulnerability in Overhang.IO (tutor-open-edx) version 20.0.2. The issue arises due to improper cache-control headers and client-side session handling, allowing unauthorized access to sensitive information via browser back button navigation post-logout.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N