VYPR

Student Management System

by Ningzichun

Source repositories

CVEs (10)

  • CVE-2023-3008HigMay 31, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in ningzichun Student Management System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument user/pass leads to sql injection. It is possible to initiate the attack remotely. The exploit…

  • CVE-2026-97646HigSep 25, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This affects an unknown function of the file admin/fun/getStudent.php. This manipulation of the argument sid causes authorization bypass. The attack is possible…

  • CVE-2026-86673HigSep 8, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connection. This manipulation causes hard-coded…

  • CVE-2023-3007MedMay 31, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in ningzichun Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file resetPassword.php of the component Password Reset Handler. The manipulation of the argument sid leads to weak…

  • CVE-2026-86674MedSep 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is the function session_start of the file login.php. The manipulation results in session fixiation. The attack can be launched…

  • CVE-2026-97647MedSep 25, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This impacts an unknown function of the file user/editLog.php. Such manipulation of the argument sid/addtime/type/reason/detail/logdate leads to…

  • CVE-2026-86672MedSep 8, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to information disclosure. The attack can be…

  • CVE-2026-97649MedSep 25, 2026
    risk 0.31cvss 4.7epss 0.00

    A flaw has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is an unknown functionality of the file example_lite.sql. Executing a manipulation can lead to use of default credentials. It is possible…

  • CVE-2026-97650MedSep 25, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function echo of the file admin/fun/addLog.php. The manipulation of the argument reason/detail leads to cross site scripting. The…

  • CVE-2026-97648MedSep 25, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function. Performing a manipulation results in cross-site request forgery. It is possible to initiate the attack remotely. The exploit is…