CVE-2025-8322 Details
Description
The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to access administrator functions, including creating, modifying, and deleting accounts. They can even escalate any account to system administrator privilege.
A missing authorization vulnerability has been identified in Ventem's e-School platform. This issue allows remote attackers with regular user privileges to access administrative functions. Exploitation of this vulnerability enables the creation, modification, and deletion of user accounts, as well as the escalation of any account to system administrator privileges.
Schools running the system on-premises should contact the vendor to confirm the update status or consider restricting access to the campus network only.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 30, 2025CISA-ADP
Assessed Jul 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.twcert.org.tw/en/cp-139-10305-2eca0-2.html | [email protected] | AdvisoryRemedy |
| https://www.twcert.org.tw/tw/cp-132-10304-6b375-1.html | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ventem e-School | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2025 | New CVE Received | [email protected] |
Volerion