<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>学生信息管理系统 (&lt;= E08f7f1d5015af407aa4cca0ada3dea189b4937e) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/%E5%AD%A6%E7%94%9F%E4%BF%A1%E6%81%AF%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F--e08f7f1d5015af407aa4cca0ada3dea189b4937e/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 31 Aug 2026 07:15:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/%E5%AD%A6%E7%94%9F%E4%BF%A1%E6%81%AF%E7%AE%A1%E7%90%86%E7%B3%BB%E7%BB%9F--e08f7f1d5015af407aa4cca0ada3dea189b4937e/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in Soarkey StudentManagement</title><link>https://feed.craftedsignal.io/briefs/2026-08-soarkey-auth-bypass/</link><pubDate>Mon, 31 Aug 2026 07:15:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-soarkey-auth-bypass/</guid><description>A vulnerability in the Administrative Servlet of Soarkey StudentManagement and 学生信息管理系统 allows remote attackers to bypass authorization via manipulation of the action argument in AdminDao.doGet.</description><content:encoded><![CDATA[<p>A critical authorization bypass vulnerability has been identified in Soarkey StudentManagement and the Student Information Management System (学生信息管理系统), specifically impacting all versions up to commit e08f7f1d5015af407aa4cca0ada3dea189b4937e. The flaw is located in the AdminDao.doGet function within the Administrative Servlet component (code/src/service/AdminDao.java). An attacker can perform remote exploitation by sending a crafted HTTP request that manipulates the 'action' argument, effectively circumventing authentication and authorization controls to access restricted administrative functions. This vulnerability is particularly concerning as functional exploit code is publicly available, allowing for ease of exploitation by unauthorized actors. The vendor has been notified of the issue but has not yet provided a patch. Defenders should monitor for anomalous HTTP requests targeting administrative endpoints that utilize the 'action' parameter.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated remote attackers to gain unauthorized access to administrative functionality within the student management platform. This could lead to the unauthorized modification, deletion, or exfiltration of sensitive student data, potentially impacting the entire user base of the affected academic or administrative institution.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor web server access logs for anomalous requests containing the 'action' parameter directed toward the AdminDao servlet, specifically looking for attempts to bypass login or gain unauthorized privileges.</li>
<li>Implement strict ingress filtering for the application's administrative web interface to limit access to known, trusted IP ranges until a vendor patch is available.</li>
<li>Audit existing deployments of Soarkey StudentManagement to confirm if the current version is vulnerable (up to commit e08f7f1d5015af407aa4cca0ada3dea189b4937e).</li>
<li>Given the public availability of the exploit, initiate a review of logs associated with the application to identify any signs of historical unauthorized administrative access.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>vulnerability</category><category>authentication-bypass</category></item></channel></rss>