NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf of the school.Referenceshttps://www.twcert.org.tw/tw/cp-132-11117-4f503-1.htmlhttps://www.twcert.org.tw/en/cp-139-11121-51e56-2.html