CVE-2025-31338 MEDIUM

CVE-2025-31338: Wisdom Master Pro - Missing Authorization

Vendor Sunnet Technology Co., Ltd.
Product Wisdom Master Pro
Weakness CWE-862 · Missing authorization
Published April 17, 2025
Last update April 17, 2025

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A missing authorization vulnerability in the retrieve teacher Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to obtain partial user data by accessing the API functionality.

Key dates

02Disclosure timeline

April 17, 2025 CVE published
April 17, 2025 Record updated