Executive brief
K12net, a school management system used for educational administration, contains a security flaw that improperly handles sensitive information. This vulnerability could allow an attacker to manipulate communication channels or gain access to private data. Such an exploit could compromise student or staff privacy and disrupt the integrity of school communications.
Technical details
A vulnerability classified as CWE-201 (Insertion of Sensitive Information Into Sent Data) exists in Atlas Educational Software K12net through version 09022026. The flaw allows for communication channel manipulation by exposing sensitive data within transmitted packets. An attacker with low-level privileges can exploit this over the network, though user interaction is required. This could result in high confidentiality impact and low impacts to integrity and availability. As of the disclosure date, the vendor has not responded to reports of this issue.
Affected products
- Atlas Educational Software Industry Ltd. Co. K12net through 09022026
Timeline
- 2026-02-09: advisory: Initial disclosure by TR-CERT (USOM)
- 2026-02-09: disclosed: NVD publication date