<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Student-Management-System (&lt;= 98760f5711cf6dc8b4adca53a9e207ca49b02ebf) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/student-management-system--98760f5711cf6dc8b4adca53a9e207ca49b02ebf/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 25 Sep 2026 02:49:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/student-management-system--98760f5711cf6dc8b4adca53a9e207ca49b02ebf/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in ningzichun student-management-system</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97646-student-management-system-auth-bypass/</link><pubDate>Fri, 25 Sep 2026 02:49:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97646-student-management-system-auth-bypass/</guid><description>A publicly disclosed authorization bypass vulnerability in the student-management-system allows remote attackers to access unauthorized student records via manipulated sid parameters.</description><content:encoded><![CDATA[<p>The ningzichun student-management-system, specifically versions up to commit 98760f5711cf6dc8b4adca53a9e207ca49b02ebf, contains an authorization bypass vulnerability (CVE-2026-97646). The flaw resides within the admin/fun/getStudent.php file, which fails to properly validate the sid argument during request processing. An unauthenticated remote attacker can exploit this weakness by manipulating the sid parameter to retrieve sensitive student data, bypassing existing access control mechanisms. Publicly available exploit code exists, increasing the risk of exploitation. As of the disclosure date, the project maintainers have not issued a response or a patch to remediate this vulnerability.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows unauthorized access to potentially sensitive student information maintained within the system. Successful exploitation leads to a compromise of confidentiality for the student database. Given the availability of public exploits, this flaw poses a high risk for organizations using this software for administrative management of student records.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for teams using this software:</p>
<ul>
<li>Immediately isolate any instances of the ningzichun student-management-system from public internet access.</li>
<li>Implement a Web Application Firewall (WAF) rule to block or inspect HTTP requests to /admin/fun/getStudent.php containing unexpected or malformed sid parameters.</li>
<li>Audit access logs for high-frequency requests or anomalous parameter values directed at the identified file.</li>
<li>If a vendor patch is unavailable, consider restricting administrative panel access to internal IP ranges via network segmentation.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>