CRITICAL🇵🇱 Wersja polska

CVE-2025-12868

CVSS 9.3v4.0pub. 2025-11-10upd. 2026-04-15

New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated remote attackers to modify the frontend code to gain administrator privileges on the website.

🤖 AI Analysis
How it works

The application bases permission verification on mechanisms operating on the browser side (client-side authentication) instead of enforcing access control on the server. Attackers can manipulate code or data transmitted by the browser — for example, by editing JavaScript, request parameters, or cookies — to bypass authentication logic. As a result, the application grants the attacker administrator privileges without verifying identity on the server side.

Impact

Attackers gain full administrator privileges on the vulnerable website, enabling them to take control of its content, settings, and user data.

Mitigation & patch

Apply patches available from the vendor according to references published by TWCERT (https://www.twcert.org.tw/en/cp-139-10492-84a10-2.html). Additionally, move all authentication and authorization logic to the server side, eliminating reliance on client-controlled data.

Who is affected

CyberTutor's New Site Server software — specific versions indicated in the vendor's references (TWCERT).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References