CVE-2025-14712
Unknown
Unknown - Not Provided
Exposure of Sensitive Information in JHENG GAO Student Assessment System
Publication date: 2025-12-15
Last updated on: 2025-12-15
Assigner: TWCERT/CC
Description
Description
Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain test accounts and password.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zhenggao | student_learning_diagnostic_and_counseling_system | * |
| jheng_gao | student_learning_assessment_and_support_system | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-497 | The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does. |