Executive brief
The sayan365 Student Management System, a web application used by educators to manage academic records, contains a security flaw that allows unauthorized access to administrative functions. An attacker can remotely view and modify student attendance and subject records without needing a username or password. This could lead to the unauthorized alteration of student data and a loss of integrity for the school's record-keeping system.
Technical details
The sayan365 student-management-system (up to commit 7f3c9ce) suffers from improper authentication (CWE-287) in multiple administrative scripts, including edit_attendance.php and edit_subject.php. The root cause is a failure to verify session variables (such as $_SESSION['username']) before processing GET and POST requests. In some cases, session_start() is missing entirely, while in others, the session is started but never validated. A remote, unauthenticated attacker can exploit this by directly accessing the affected PHP files with a target ID parameter to view or modify attendance and subject data. As of the advisory date, the project has not responded to the issue reports.
Affected products
- sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800
Timeline
- 2026-05-14: disclosed: Issue reported to the developer via GitHub issues 3 and 4.
- 2026-06-02: advisory: CVE-2026-10619 published.
References
- https://github.com/sayan365/student-management-system/
- https://github.com/sayan365/student-management-system/issues/3
- https://github.com/sayan365/student-management-system/issues/4
- https://vuldb.com/cve/CVE-2026-10619
- https://vuldb.com/submit/829545
- https://vuldb.com/submit/829562
- https://vuldb.com/submit/829566