Serosoft's vulnerability profile centers on its academic student information system, a niche but critical application serving educational institutions where access control and data confidentiality directly affect student privacy and institutional compliance. Vulnerabilities affecting this vendor skew toward serious outcomes and concentrate in web application layer issues—cross-site scripting, missing and bypassable authorization controls, and sensitive data exposure—that reflect the authentication and role-management demands of systems handling student records and administrative functions. Defenders should treat this vendor's updates as high-priority for deployed institutions and audit authorization enforcement and input handling in particular; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Serosoft over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-27583CRITICAL Incorrect access control in the component /rest/staffResource/findAllUsersAcrossOrg of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows c | Mar 3, 2025 | 9.1 | 28 | NO | NO |
CVE-2025-25950HIGH Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows create and modif | Mar 3, 2025 | 8.1 | 23 | NO | NO |
CVE-2025-25951HIGH An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows | Mar 3, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-25953MEDIUM Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 was discovered to contain an Azure JWT access token exposure. This vulnerability allows authent | Mar 3, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-25952MEDIUM An Insecure Direct Object References (IDOR) in the component /getStudemtAllDetailsById?studentId=XX of Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v | Mar 3, 2025 | 6.5 | 18 | NO | NO |
CVE-2025-27585MEDIUM A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web | Mar 3, 2025 | 5.4 | 16 | NO | NO |
CVE-2025-27584MEDIUM A stored cross-site scripting (XSS) vulnerability in Serosoft Solutions Pvt Ltd Academia Student Information System (SIS) EagleR v1.0.118 allows attackers to execute arbitrary web | Mar 3, 2025 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Serosoft.
Media articles that mention a CVE ID that affects a product developed by Serosoft — matched by CVE ID, not by vendor name.