CVE-2025-65681
LOWOverhang.IO <20.0.2 - Info Disclosure
Title source: llmDescription
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks.
Exploits (1)
Scores
CVSS v3
3.3
EPSS
0.0001
EPSS Percentile
0.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Details
CWE
CWE-524
CWE-384
Status
published
Products (2)
edly/tutor
20.0.2
pypi/tutor
0PyPI
Published
Nov 26, 2025
Tracked Since
Feb 18, 2026