Junglewise Threat Intelligence

CVE-2025-1469: Turtek Software Eyotek authorization bypass via user-controlled key

CVE-2025-1469 · Severity: high · CVSS 7.5 · Published 2025-07-21

Executive brief

Turtek Software Eyotek, an educational management system, contains a security flaw that allows unauthorized access to sensitive information. By manipulating specific identifiers in web requests, an attacker can view data they are not permitted to see. This could lead to the exposure of confidential student or institutional records, potentially impacting the organization's privacy compliance and reputation.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639 (Authorization Bypass Through User-Controlled Key), exists in Turtek Software Eyotek versions prior to 11.03.2025. The application fails to properly validate that the requesting user has the authority to access a resource identified by a user-provided key or identifier. A remote, unauthenticated attacker can exploit this by modifying these identifiers in network requests to access sensitive data belonging to other users or the system. The vulnerability is exploitable over the network with low complexity and requires no user interaction. A patch was released on March 11, 2025.

Affected products

  • Turtek Software Eyotek before 11.03.2025

Timeline

  • 2025-03-11: patched: Vendor released fix in version dated 11.03.2025
  • 2025-07-21: disclosed: Initial NVD publication
  • 2025-07-21: advisory: TR-25-0163 advisory published by USOM

References

Related threats