Junglewise Threat Intelligence

CVE-2026-10619: sayan365 student-management-system improper authentication in administrative endpoints

CVE-2026-10619 · Severity: high · CVSS 7.3 · Published 2026-06-02

Technologies: Sayan365 Student Management System.

Executive brief

The sayan365 Student Management System, a web application used by educators to manage academic records, contains a security flaw that allows unauthorized access to administrative functions. An attacker can remotely view and modify student attendance and subject records without needing a username or password. This could lead to the unauthorized alteration of student data and a loss of integrity for the school's record-keeping system.

Technical details

The sayan365 student-management-system (up to commit 7f3c9ce) suffers from improper authentication (CWE-287) in multiple administrative scripts, including edit_attendance.php and edit_subject.php. The root cause is a failure to verify session variables (such as $_SESSION['username']) before processing GET and POST requests. In some cases, session_start() is missing entirely, while in others, the session is started but never validated. A remote, unauthenticated attacker can exploit this by directly accessing the affected PHP files with a target ID parameter to view or modify attendance and subject data. As of the advisory date, the project has not responded to the issue reports.

Affected products

  • sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800

Timeline

  • 2026-05-14: disclosed: Issue reported to the developer via GitHub issues 3 and 4.
  • 2026-06-02: advisory: CVE-2026-10619 published.

References