CVE-2019-12837: Gencat Portal D'acces A La Universitat

Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.

The Java API in accesuniversitat.gencat.cat 1.7.5 allows remote attackers to get personal information of all registered students via several API endpoints.

Affected products

  • Gencat Portal D'acces A La Universitat: version 1.7.5 only

Published 2019-12-31. Last modified 2026-06-17.