CVE Feed

    Dashboard / CVE / CVE-2025-69727

    CVE-2025-69727

    An Incorrect Access Control vulnerability exists in INDEX-EDUCATION PRONOTE prior to 2025.2.8. The affected components (index.js and composeUrlImgPhotoIndividu) allow the construction of direct URLs to user profile images based solely on predictable identifiers such as user IDs and names. Due to missing authorization checks and lack of rate-limiting when generating or accessing these URLs, an unauthenticated or unauthorized actor may retrieve profile pictures of users by crafting requests with guessed or known identifiers.

    Published:Mar 16, 2026
    Last Modified:Mar 23, 2026
    EPS:Mar 16, 2026
    EPSS Score:0.00037
    CVSS Score:5.3

    Affected Products

    Vendor
    Index-education
    Product
    Pronote

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High