Junglewise Threat Intelligence

CVE-2025-2301: Akbim Software Online Exam Registration authorization bypass via IDOR

CVE-2025-2301 · Severity: medium · CVSS 4.4 · Published 2025-07-21

Executive brief

Akbim Software's Online Exam Registration system, used by educational institutions to manage student sign-ups for exams, contains a security flaw. An attacker with existing high-level access could manipulate system identifiers to view sensitive information they are not authorized to see. This could lead to the exposure of student data or exam-related records, potentially impacting privacy and institutional reputation.

Technical details

An Authorization Bypass Through User-Controlled Key (CWE-639) exists in Akbim Software Online Exam Registration versions prior to 2025-03-14. The vulnerability occurs when the application uses an identifier provided by the user to access a record without sufficiently verifying that the user has the necessary permissions for that specific record. A remote attacker with high privileges can exploit this by modifying parameters (such as IDs in a URL or POST request) to access sensitive data belonging to other entities. The attack requires a high level of complexity and existing high-level administrative or system privileges. A fix was released on March 14, 2025.

Affected products

  • Akbim Software Online Exam Registration before 14.03.2025

Timeline

  • 2025-03-14: patched: Vendor released a fix for the affected software.
  • 2025-07-21: disclosed: Initial advisory publication.

References