Junglewise Threat Intelligence

CVE-2025-41029: Zeon Global Tech Zeon Academy Pro SQL injection in continue-upload.php

CVE-2025-41029 · Severity: info · CVSS 9.3 · Published 2026-04-21

Executive brief

Zeon Academy Pro, a school management system, contains a critical security flaw that allows unauthorized individuals to access and manipulate its database. By sending a specially crafted request, an attacker could view sensitive student or staff records, modify existing data, or delete entire databases. This could lead to significant data breaches, loss of academic records, and total disruption of school administrative operations.

Technical details

A SQL injection vulnerability exists in Zeon Academy Pro due to improper neutralization of special elements in the 'phonenumber' parameter within the '/private/continue-upload.php' component. An unauthenticated remote attacker can exploit this by sending a specially crafted POST request to the affected endpoint. Successful exploitation allows for full database interaction, including data exfiltration (CWE-89) and unauthorized modification or deletion of records. As of the advisory date, no patch or solution has been reported, making this a zero-day vulnerability.

Affected products

  • Zeon Global Tech Zeon Academy Pro

Timeline

  • 2026-04-02: advisory: Initial advisory published by INCIBE-CERT
  • 2026-04-21: disclosed: CVE-2025-41029 published to NVD

References