PT-2026-83610 · Sambitraj · Student Management System
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
sambitraj Student Management System versions prior to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5
Description
Improper authorization occurs in the Student Dashboard component when the
roll no argument is manipulated. This issue is triggered within the mysqli query() function located in the student dashboard.php file and can be exploited remotely.Recommendations
Update sambitraj Student Management System to a version later than 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5.
As a temporary mitigation, restrict access to the
student dashboard.php file or avoid using the roll no parameter until a patch is applied.Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Student Management System