2025-04-17

Wisdom Master Pro - Missing Authorization

ZUSOART ID ZA-2025-01
CVE ID CVE-2025-31338
Vulnerability Type CWE-862: Missing Authorization
CVSS 4.0 Base CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N(6.9)
Description A missing authorization vulnerability in the retrieve teacher Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to obtain partial user data by accessing the API functionality.
Vendor SUNNET Technology Co., Ltd.
Product
Category Version affected
Wisdom Master Pro From 5.0 through 5.2
Product Support Contact SUNNET Technology for version updates.
Release date 2025/04/17
Credit Kuang Ming Chang of ZUSO ART
top