Junglewise Threat Intelligence

CVE-2026-10777: ealpha072 Student-Management-System improper authentication in admin backend

CVE-2026-10777 · Severity: high · CVSS 7.3 · Published 2026-06-03

Technologies: Ealpha072 Student Management System.

Executive brief

A vulnerability in the ealpha072 Student-Management-System allows unauthorized individuals to bypass the login screen and access the administrative dashboard. This software is used to manage student records, courses, and department data. An attacker can exploit this flaw to view or modify sensitive educational information and perform administrative tasks without a valid username or password.

Technical details

The Student-Management-System suffers from an improper authentication vulnerability (CWE-287) within its administrative backend. The root cause is located in 'admin/config.php', where the 'session_start()' function call is commented out, preventing the initialization of PHP sessions. Because sessions are not started, subsequent checks for authentication variables in 'admin/dashboard.php' and other administrative pages fail to validate the user's state. A remote, unauthenticated attacker can exploit this by directly navigating to administrative URLs, gaining full access to CRUD operations for students, courses, and departments. As of the advisory date, the vendor has not responded to the issue report.

Affected products

  • ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08

Timeline

  • 2026-05-16: disclosed: Issue reported on GitHub repository
  • 2026-06-03: advisory: CVE published and NVD entry created

References