CVE-2025-10024
7.5EXERT Computer Technologies Software Ltd. Co. · Education Management System
An authorization bypass vulnerability in the EXERT Computer Technologies Education Management System allows unauthenticated attackers to perform parameter injection.
Executive summary
A critical authorization bypass vulnerability in the EXERT Education Management System exposes sensitive data to unauthenticated attackers via parameter injection.
Vulnerability
This vulnerability is classified as CWE-639, Authorization Bypass Through User-Controlled Key, which permits an unauthenticated attacker to manipulate parameters to gain unauthorized access to sensitive information.
Business impact
The exploitation of this vulnerability poses a significant risk to data confidentiality, as it allows unauthorized access to sensitive records within the Education Management System. Given the CVSS score of 7.5, which indicates a High severity, this flaw could lead to substantial regulatory non-compliance and reputational damage if student or institutional data is exfiltrated.
Remediation
Immediate Action: Contact the vendor or consult the official USOM advisory to obtain the necessary security updates or configuration changes to address the parameter injection flaw.
Proactive Monitoring: Monitor system access logs for anomalous parameter structures or unexpected access patterns originating from external, unauthenticated sources.
Compensating Controls: Implement a Web Application Firewall (WAF) to filter and sanitize incoming request parameters, which may help block injection attempts until a formal patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this authorization bypass necessitates immediate attention from IT security administrators. Organizations utilizing the EXERT Education Management System should prioritize verifying their version status and applying vendor-supplied updates as soon as they become available to prevent potential data exposure.
Sources
Originally found and disclosed by Serhat YAPICI, per the CVE Program record.