CVE-2026-2984
Plain English Summary
AI-powered analysis for quick understanding
An attacker can remotely crash the student result management system by manipulating a specific function in the admin panel, which can lead to a denial of service. This vulnerability is easy to exploit, as the method to do so is publicly available.
Technical Description
A vulnerability was identified in SourceCodester Student Result Management System 1.0. This affects an unknown function of the file /admin/core/drop_user.php. Such manipulation of the argument ID leads to denial of service. The attack can be executed remotely. The exploit is publicly available and might be used.
CVSS Vector Analysis
Vector String
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 23, 2026
about 1 month ago
Last Modified
Feb 24, 2026
about 1 month ago
Vendor
munyweki
Product
student result management system
Related Vulnerabilities
An attacker can exploit a flaw in the student result management system to gain unauthorized access to sensitive user data by manipulating a specific file upload function. This vulnerability can be exploited remotely, meaning the attacker does not need physical access to the system, and it has been publicly disclosed, increasing the risk of attacks.
An attacker can remotely access and manipulate the Student Result Management System due to improper access controls in a specific file, potentially allowing them to change settings or access sensitive information. This vulnerability requires no special privileges, making it easier for attackers to exploit it.