CVE-2025-25953

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Mar 3, 2025
Updated: Mar 5, 2025
CWE ID 862

Summary

CVE-2025-25953 is a newly identified vulnerability affecting Serosoft Solutions Pvt Ltd's Academia Student Information System (SIS) EagleR version 1.0.118. Hackers can exploit this Azure JWT access token exposure to escalate privileges and gain unauthorized access to sensitive information. The vulnerability poses a significant risk to the confidentiality and integrity of data handled by the affected system. Organizations using this version of SIS EagleR are strongly advised to apply the necessary patches or updates to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share