Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28211 | Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time Password (OTP). Prior to version 1.0.1, even if a secure random number generator is used, the short length and limited range (1000–9999) results in only 9000 possible combinations. This small keyspace makes the OTP highly vulnerable to brute-force attacks, especially in the absence of strong rate-limiting or lockout mechanisms. Version 1.0.1 fixes the issue. |
Fri, 05 Sep 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Schule111
Schule111 schule School Management System |
|
| CPEs | cpe:2.3:a:schule111:schule_school_management_system:1.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Schule111
Schule111 schule School Management System |
|
| Metrics |
cvssV3_1
|
Fri, 23 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 22 May 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time Password (OTP). Prior to version 1.0.1, even if a secure random number generator is used, the short length and limited range (1000–9999) results in only 9000 possible combinations. This small keyspace makes the OTP highly vulnerable to brute-force attacks, especially in the absence of strong rate-limiting or lockout mechanisms. Version 1.0.1 fixes the issue. | |
| Title | Schule Has Insecure OTP Length, is Susceptible to Brute-Force Attacks | |
| Weaknesses | CWE-521 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-23T13:56:37.894Z
Reserved: 2025-05-19T15:46:00.395Z
Link: CVE-2025-48372
Updated: 2025-05-23T13:56:31.257Z
Status : Analyzed
Published: 2025-05-22T21:15:36.640
Modified: 2025-09-05T14:15:28.703
Link: CVE-2025-48372
No data.
OpenCVE Enrichment
No data.
EUVD