Executive brief
A vulnerability in the ealpha072 Student-Management-System allows unauthorized individuals to bypass the login screen and access the administrative dashboard. This software is used to manage student records, courses, and department data. An attacker can exploit this flaw to view or modify sensitive educational information and perform administrative tasks without a valid username or password.
Technical details
The Student-Management-System suffers from an improper authentication vulnerability (CWE-287) within its administrative backend. The root cause is located in 'admin/config.php', where the 'session_start()' function call is commented out, preventing the initialization of PHP sessions. Because sessions are not started, subsequent checks for authentication variables in 'admin/dashboard.php' and other administrative pages fail to validate the user's state. A remote, unauthenticated attacker can exploit this by directly navigating to administrative URLs, gaining full access to CRUD operations for students, courses, and departments. As of the advisory date, the vendor has not responded to the issue report.
Affected products
- ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08
Timeline
- 2026-05-16: disclosed: Issue reported on GitHub repository
- 2026-06-03: advisory: CVE published and NVD entry created