CVE-2025-70029
HIGHSunbirdEd-portal <1.13.4 - Info Disclosure
Title source: llmDescription
An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTP request options
Scores
CVSS v3
7.5
EPSS
0.0002
EPSS Percentile
5.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-295
Status
draft
Timeline
Published
Feb 11, 2026
Tracked Since
Feb 18, 2026