{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/student-management-system--98760f5711cf6dc8b4adca53a9e207ca49b02ebf/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ningzichun:student-management-system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-97646"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["student-management-system (\u003c= 98760f5711cf6dc8b4adca53a9e207ca49b02ebf)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ningzichun"],"content_html":"\u003cp\u003eThe ningzichun student-management-system, specifically versions up to commit 98760f5711cf6dc8b4adca53a9e207ca49b02ebf, contains an authorization bypass vulnerability (CVE-2026-97646). The flaw resides within the admin/fun/getStudent.php file, which fails to properly validate the sid argument during request processing. An unauthenticated remote attacker can exploit this weakness by manipulating the sid parameter to retrieve sensitive student data, bypassing existing access control mechanisms. Publicly available exploit code exists, increasing the risk of exploitation. As of the disclosure date, the project maintainers have not issued a response or a patch to remediate this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthorized access to potentially sensitive student information maintained within the system. Successful exploitation leads to a compromise of confidentiality for the student database. Given the availability of public exploits, this flaw poses a high risk for organizations using this software for administrative management of student records.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for teams using this software:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately isolate any instances of the ningzichun student-management-system from public internet access.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to block or inspect HTTP requests to /admin/fun/getStudent.php containing unexpected or malformed sid parameters.\u003c/li\u003e\n\u003cli\u003eAudit access logs for high-frequency requests or anomalous parameter values directed at the identified file.\u003c/li\u003e\n\u003cli\u003eIf a vendor patch is unavailable, consider restricting administrative panel access to internal IP ranges via network segmentation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T02:49:59Z","date_published":"2026-09-25T02:49:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97646-student-management-system-auth-bypass/","summary":"A publicly disclosed authorization bypass vulnerability in the student-management-system allows remote attackers to access unauthorized student records via manipulated sid parameters.","title":"Authorization Bypass in ningzichun student-management-system","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97646-student-management-system-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Student-Management-System (\u003c= 98760f5711cf6dc8b4adca53a9e207ca49b02ebf)","version":"https://jsonfeed.org/version/1.1"}