Executive brief
Zeon Academy Pro, a school management system, contains a critical security flaw that allows unauthorized individuals to access and manipulate its database. By sending a specially crafted request, an attacker could view sensitive student or staff records, modify existing data, or delete entire databases. This could lead to significant data breaches, loss of academic records, and total disruption of school administrative operations.
Technical details
A SQL injection vulnerability exists in Zeon Academy Pro due to improper neutralization of special elements in the 'phonenumber' parameter within the '/private/continue-upload.php' component. An unauthenticated remote attacker can exploit this by sending a specially crafted POST request to the affected endpoint. Successful exploitation allows for full database interaction, including data exfiltration (CWE-89) and unauthorized modification or deletion of records. As of the advisory date, no patch or solution has been reported, making this a zero-day vulnerability.
Affected products
- Zeon Global Tech Zeon Academy Pro
Timeline
- 2026-04-02: advisory: Initial advisory published by INCIBE-CERT
- 2026-04-21: disclosed: CVE-2025-41029 published to NVD