VendorsAcademiaERPstudent_information_systemall versions
Vulnerabilities

AcademiaERP Student Information System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2024-53636
An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.
Published 2025-04-26 · Analyzed
9.8EPSS 0.016
CVE-2025-25948
Incorrect access control in the component /rest/staffResource/create of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modify user accounts, including an Administrator account.
Published 2025-03-03 · Analyzed
9.1EPSS 0.069
CVE-2025-25949
A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the User ID parameter at /rest/staffResource/update.
Published 2025-03-03 · Analyzed
5.4EPSS 0.003