The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to access administrator functions, including creating, modifying, and deleting accounts. They can even escalate any account to system administrator privilege.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 30 Jul 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ventem
Ventem e-school |
|
| Vendors & Products |
Ventem
Ventem e-school |
Wed, 30 Jul 2025 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to access administrator functions, including creating, modifying, and deleting accounts. They can even escalate any account to system administrator privilege. | |
| Title | Ventem|e-School - Missing Authorization | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published: 2025-07-30T02:49:22.021Z
Updated: 2025-07-30T13:43:59.436Z
Reserved: 2025-07-30T01:48:12.532Z
Link: CVE-2025-8322
Updated: 2025-07-30T13:43:54.136Z
Status : Deferred
Published: 2025-07-30T04:16:10.193
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-8322
No data.