CVE-2025-10024

7.5

EXERT Computer Technologies Software Ltd. Co. · Education Management System

An authorization bypass vulnerability in the EXERT Computer Technologies Education Management System allows unauthenticated attackers to perform parameter injection.

Executive summary

A critical authorization bypass vulnerability in the EXERT Education Management System exposes sensitive data to unauthenticated attackers via parameter injection.

Vulnerability

This vulnerability is classified as CWE-639, Authorization Bypass Through User-Controlled Key, which permits an unauthenticated attacker to manipulate parameters to gain unauthorized access to sensitive information.

Business impact

The exploitation of this vulnerability poses a significant risk to data confidentiality, as it allows unauthorized access to sensitive records within the Education Management System. Given the CVSS score of 7.5, which indicates a High severity, this flaw could lead to substantial regulatory non-compliance and reputational damage if student or institutional data is exfiltrated.

Remediation

Immediate Action: Contact the vendor or consult the official USOM advisory to obtain the necessary security updates or configuration changes to address the parameter injection flaw.

Proactive Monitoring: Monitor system access logs for anomalous parameter structures or unexpected access patterns originating from external, unauthenticated sources.

Compensating Controls: Implement a Web Application Firewall (WAF) to filter and sanitize incoming request parameters, which may help block injection attempts until a formal patch is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this authorization bypass necessitates immediate attention from IT security administrators. Organizations utilizing the EXERT Education Management System should prioritize verifying their version status and applying vendor-supplied updates as soon as they become available to prevent potential data exposure.

Sources

Originally found and disclosed by Serhat YAPICI, per the CVE Program record.