CVE-2025-14712
Exposure of Sensitive Information in JHENG GAO Student Assessment System
Publication date: 2025-12-15
Last updated on: 2025-12-15
Assigner: TWCERT/CC
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zhenggao | student_learning_diagnostic_and_counseling_system | * |
| jheng_gao | student_learning_assessment_and_support_system | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-497 | The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Exposure of Sensitive Information flaw in the Student Learning Assessment and Support System developed by JHENG GAO. It allows unauthenticated remote attackers to access a specific page within the system and obtain test account usernames and passwords without needing any privileges or user interaction. [1, 2]
How can this vulnerability impact me? :
The vulnerability can impact you by allowing unauthorized remote attackers to view sensitive information such as test account credentials. This could lead to unauthorized access to the system using these test accounts, potentially compromising confidentiality. However, it does not affect data integrity or system availability. [1, 2]
What immediate steps should I take to mitigate this vulnerability?
Immediate mitigation steps include contacting JHENG GAO or ZhengGao to verify that your system has been updated with the patch released on October 16, 2025. If updates cannot be confirmed or applied immediately, it is recommended to disable external access to the Student Learning Assessment and Support System and restrict its usage to the internal network only. [1, 2]