Vulnerability Details CVE-2025-65594
OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthorized database write operations relating to the data of other users.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 4.0%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2025-65594
-
cpe:2.3:a:os4ed:opensis:4.5
-
cpe:2.3:a:os4ed:opensis:4.6
-
cpe:2.3:a:os4ed:opensis:4.7
-
cpe:2.3:a:os4ed:opensis:4.8
-
cpe:2.3:a:os4ed:opensis:4.8.1
-
cpe:2.3:a:os4ed:opensis:4.9
-
cpe:2.3:a:os4ed:opensis:5.0
-
cpe:2.3:a:os4ed:opensis:5.1
-
cpe:2.3:a:os4ed:opensis:5.2
-
cpe:2.3:a:os4ed:opensis:5.3
-
cpe:2.3:a:os4ed:opensis:7.0
-
cpe:2.3:a:os4ed:opensis:7.1
-
cpe:2.3:a:os4ed:opensis:7.2
-
cpe:2.3:a:os4ed:opensis:7.3
-
cpe:2.3:a:os4ed:opensis:7.4
-
cpe:2.3:a:os4ed:opensis:7.5
-
cpe:2.3:a:os4ed:opensis:7.6
-
cpe:2.3:a:os4ed:opensis:8.0
-
cpe:2.3:a:os4ed:opensis:9.0