Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain test accounts and password.
Advisories

No advisories yet.

Fixes

Solution

JHENG GAO completed vulnerability remediation on October 16, 2025, and has been progressively completing version updates. If the system is deployed on-premises, please contact JHENG GAO to confirm the update status, or evaluate disabling external services and allowing access only within the intranet.


Workaround

No workaround given by the vendor.

History

Mon, 15 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 15 Dec 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Jhenggao
Jhenggao student Learning Assessment And Support System
Vendors & Products Jhenggao
Jhenggao student Learning Assessment And Support System

Mon, 15 Dec 2025 05:45:00 +0000

Type Values Removed Values Added
Description Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain test accounts and password.
Title JHENG GAO|Student Learning Assessment and Support System - Exposure of Sensitive Information
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2025-12-15T15:25:16.324Z

Reserved: 2025-12-15T03:05:21.972Z

Link: CVE-2025-14712

cve-icon Vulnrichment

Updated: 2025-12-15T15:25:11.056Z

cve-icon NVD

Status : Received

Published: 2025-12-15T06:15:43.263

Modified: 2025-12-15T06:15:43.263

Link: CVE-2025-14712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-15T14:05:43Z

Weaknesses