9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated remote attackers to modify the frontend code to gain administrator privileges on the website.
AI Analysis
Use of Client-Side Authentication vulnerability allowing unauthenticated remote attackers to gain administrator privileges
Basic Information
ID
CVE-2025-12868
Source
twcert
Published
Nov 10, 2025 at 03:14
Affected Product
Vendor
CyberTutor
Product
New Site Server
Affected Versions
CyberTutor New Site Server 0
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
CyberTutor
Product
New Site Server