An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks.
{
"nvd_published_at": "2025-11-26T19:15:49Z",
"github_reviewed": true,
"github_reviewed_at": "2025-12-01T22:57:57Z",
"severity": "LOW",
"cwe_ids": [
"CWE-384"
]
}