Unknown · Studentinfo · CVE-2026-100897
**Name of the Vulnerable Software and Affected Versions**
fuzui StudentInfo versions up to fcc42a639ec7cef620651bfd0f07ebb660529e3f
**Description**
A remote authorization bypass exists in the Password Change Endpoint within the file `/StudentInfo/StudentHandler/moditypasswordstu`. The issue occurs when the `sid` or `tid` arguments are manipulated, allowing an attacker to bypass security checks.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.