Impact
NewSiteServer includes a missing authentication flaw that allows attackers to trigger the email‑sending routine without credentials. By calling a public endpoint, an unauthenticated user can instruct the server to send messages to any recipient, effectively impersonating the institution. This opens the possibility for spam, phishing, or other malicious uses of the school's email system, compromising its reputation and potentially exposing sensitive recipients.
Affected Systems
The vulnerability affects CyberTutor's NewSiteServer (NSS). No specific product versions are listed in the CNA data, so all currently deployed versions may be susceptible until the vendor issues an official fix.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium‑to‑high risk, while the EPSS score is not available. The flaw is remotely exploitable over the network via the unauthenticated email endpoint, as inferred from the description. Although the vulnerability is not yet listed in the CISA KEV catalog, the missing authentication (CWE‑306) suggests that exploitation is feasible if the endpoint is publicly reachable.
OpenCVE Enrichment