Back to all
2025-04-17

Wisdom Master Pro - Missing Authorization

ZUSOART ID
ZA-2025-01
CVE ID
CVE-2025-31338
Vulnerability Type
CWE-862: Missing Authorization
CVSS 4.0 Base
6.9
Description

A missing authorization vulnerability in the retrieve teacher Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to obtain partial user data by accessing the API functionality.

Vendor
SUNNET Technology Co., Ltd.
Product
Category
Version affected
Wisdom Master Pro
From 5.0 through 5.2
Mitigations

Contact SUNNET Technology for version updates.

Release date
2025-04-17
Credit

Kuang Ming Chang of ZUSO ART