Impact
WeenyGenius, a computer lab management system, has an origin validation error that lets an attacker on the same local network spoof the teacher workstation. By sending broadcast packets, the attacker can make student computers attempt to connect to the attacker’s machine, potentially allowing the attacker to receive those connections and launch further malicious activity.
Affected Systems
The vulnerability affects howyar technologies’ WeenyGenius system for any deployed instance that has not applied the vendor’s security update. The vendor recommends upgrading to version 12.3.033 or later to remediate the flaw.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker does not need authentication and only needs to be on the same network segment. Because the exploit is straightforward—sending a simple broadcast packet—the risk is significant in environments where student computers share the LAN with untrusted devices. The attacker could redirect traffic from student machines to an attacker‑controlled host, providing a footholds for further network compromise.
OpenCVE Enrichment