CVE-2025-7708
Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation.This issue affects k12net: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
- EPSS probability
- 0.26%
- CWE
- CWE-201
- Published
- 2026-02-09
- Last modified
- 2026-08-13
Affected products
- Atlas Educational Software Industry Ltd. Co. k12net
Weakness type
Related vulnerabilities
- CVE-2026-24477 — AnythingLLM has key leak in `systemSettings.js`
- CVE-2026-47717 — FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations
- CVE-2026-27934 — Discourse leaks private topic title and post excerpt via user action API endpoint
- CVE-2025-11500 — Credentials exposure in tinycontrol devices
- CVE-2020-37093 — Netis E1+ 1.2.32533 - Unauthenticated WiFi Password Leak
- CVE-2026-27516 — Binardat 10G08-0800GSM Network Switch Plaintext Password Exposure
- CVE-2025-66566 — yawkat LZ4 Java has a possible information leak in Java safe decompressor
- CVE-2026-8924 — trailing dot domain super cookie