Unknown · Student Management System · CVE-2026-97647
**Name of the Vulnerable Software and Affected Versions**
ningzichun student-management-system versions up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf
**Description**
A remote authorization bypass exists in the file `user/editLog.php`. This issue occurs when the arguments `sid`, `addtime`, `type`, `reason`, `detail`, or `logdate` are manipulated, allowing an attacker to bypass security checks.
**Recommendations**
As a temporary workaround, restrict access to the file `user/editLog.php` to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.