Junglewise Threat Intelligence

CVE-2025-5681: Turtek Software Eyotek authorization bypass via user-controlled key

CVE-2025-5681 · Severity: medium · CVSS 6.5 · Published 2025-07-21

Executive brief

Turtek Software Eyotek, an educational management system, contains a security flaw that allows unauthorized access to sensitive information. By manipulating specific identifiers in web requests, an attacker could potentially view data belonging to other users or the institution. This could lead to the exposure of private student or administrative records, impacting the organization's data privacy compliance and reputation.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639 (Authorization Bypass Through User-Controlled Key), exists in Turtek Software Eyotek versions prior to 2025-06-23. The application fails to properly validate if the requesting user has the authority to access a specific resource identified by a user-supplied key or ID. A remote attacker can exploit this by modifying parameters in a network request to access sensitive data associated with other identifiers. While the attack vector is network-based, the CVSS metric suggests some level of user interaction (UI:R) may be required for successful exploitation. A patch was released on June 23, 2025.

Affected products

  • Turtek Software Eyotek before 23.06.2025

Timeline

  • 2025-06-23: patched: Vendor released fix for Eyotek software.
  • 2025-07-21: disclosed: CVE-2025-5681 published.

References

Related threats