CVE-2026-2983
Plain English Summary
AI-powered analysis for quick understanding
An attacker can exploit a flaw in the student result management system to gain unauthorized access to sensitive user data by manipulating a specific file upload function. This vulnerability can be exploited remotely, meaning the attacker does not need physical access to the system, and it has been publicly disclosed, increasing the risk of attacks.
Technical Description
A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the component Bulk Import. This manipulation of the argument File causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
CVSS Vector Analysis
Vector String
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 23, 2026
about 1 month ago
Last Modified
Feb 24, 2026
about 1 month ago
Vendor
munyweki
Product
student result management system
Related Vulnerabilities
An attacker can remotely crash the student result management system by manipulating a specific function in the admin panel, which can lead to a denial of service. This vulnerability is easy to exploit, as the method to do so is publicly available.
An attacker can remotely access and manipulate the Student Result Management System due to improper access controls in a specific file, potentially allowing them to change settings or access sensitive information. This vulnerability requires no special privileges, making it easier for attackers to exploit it.