VYPR

StudentManage

by DayCloud

CVEs (6)

  • CVE-2025-50585HigJul 18, 2025
    risk 0.57cvss 8.8epss 0.00

    StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.

  • CVE-2025-2351HigMar 16, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical was found in DayCloud StudentManage 1.0. This vulnerability affects unknown code of the file /admin/adminScoreUrl of the component Login Endpoint. The manipulation of the argument query leads to sql injection. The attack can be initiated…

  • CVE-2025-50586MedJul 18, 2025
    risk 0.42cvss 6.5epss 0.00

    StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).

  • CVE-2025-50583MedJul 18, 2025
    risk 0.31cvss 4.8epss 0.00

    StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module.

  • CVE-2025-50582MedJul 18, 2025
    risk 0.31cvss 4.8epss 0.00

    StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Course module.

  • CVE-2025-50584MedJul 18, 2025
    risk 0.31cvss 4.8epss 0.00

    StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Teacher module.