在 SourceCodester 班级和考试日程管理系统 1.0 中发现了一个漏洞。受影响的组件“用户账户更新”中,文件 中的某个未知函数存在安全问题。通过操纵参数 ,可导致不恰当的授权行为。该攻击可以远程发起。此漏洞已被公开披露,攻击者可能已利用该漏洞进行攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SourceCodester | Class and Exam Timetabling System | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Class and Exam Timetabling System | 1.0 |
cpe:2.3:a:sourcecodester:class_and_exam_timetabling_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78060 | 4.3 MEDIUM | SourceCodester Stock Management System getOrderReport.php cross site scripting |
| CVE-2026-78059 | 4.3 MEDIUM | SourceCodester Stock Management System printOrder.php cross site scripting |
| CVE-2026-78055 | 4.3 MEDIUM | SourceCodester Class and Exam Timetabling System BSIT2.php cross site scripting |
| CVE-2026-78054 | 4.3 MEDIUM | SourceCodester Class and Exam Timetabling System BSIS1.php cross site scripting |
No comments yet