在 ningzichun student-management-system 版本最高至 98760f5711cf6dc8b4adca53a9e207ca49b02ebf 中发现了一个安全弱点。该问题影响文件 admin/fun/getStudent.php 中的一个未知函数。通过操控参数 sid,可导致授权绕过(authorization bypass)。该漏洞可通过远程方式被利用。目前相关利用代码(exploit)已向公众公开,存在被用于攻击的风险。项目方已通过 issue 报告早期获知该问题,但至今尚未作出回
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ningzichun | student-management-system | 98760f5711cf6dc8b4adca53a9e207ca49b02ebf |
cpe:2.3:a:ningzichun:student-management-system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97647 | 5.3 MEDIUM | ningzichun student-management-system editLog.php authorization |
| CVE-2026-97649 | 4.7 MEDIUM | ningzichun student-management-system example_lite.sql default credentials |
| CVE-2026-97648 | 4.3 MEDIUM | ningzichun student-management-system cross-site request forgery |
| CVE-2026-97650 | 4.3 MEDIUM | ningzichun student-management-system addLog.php echo cross site scripting |
No comments yet