CVE-2025-3849 | YXJ2018 SpringBoot-Vue-OnlineExam 1.0 /api/studentPWD studentId unverified password change (Issue 74)
A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects unknown code of the file /api/studentPWD. The manipulation of the argument studentId leads to unverified password change.
This vulnerability was named CVE-2025-3849. The attack can be initiated remotely. Furthermore, there is an exploit available.