Executive brief
A security vulnerability has been identified in the EXERT Education Management System, a platform used for managing educational institutions and student data. An attacker can bypass security controls by manipulating specific data keys or parameters within the system. This could allow unauthorized access to sensitive information, potentially compromising student or administrative records.
Technical details
An Authorization Bypass Through User-Controlled Key (CWE-639) exists in the EXERT Computer Technologies Education Management System. The vulnerability stems from improper validation of user-supplied identifiers or keys, which allows for Parameter Injection. A remote, unauthenticated attacker can exploit this by modifying request parameters to access records or resources belonging to other users. The vulnerability is present in versions through September 23, 2025. Successful exploitation results in a high impact on confidentiality.
Affected products
- EXERT Computer Technologies Software Ltd. Co. Education Management System through 23.09.2025
Timeline
- 2026-01-22: advisory: Initial publication of the CVE record.