Junglewise Threat Intelligence

CVE-2026-11336: tittuvarghese CollegeManagementSystem improper authorization in admin_page.php

CVE-2026-11336 · Severity: medium · CVSS 6.3 · Published 2026-06-05

Technologies: Tittuvarghese College Management System, Tittuvarghese CollegeManagementSystem. Vendors: Tittuvarghese.

Executive brief

A vulnerability in the CollegeManagementSystem software allows students or other low-privileged users to access the administrative dashboard. This system is used to manage engineering college operations, including student records and grades. An attacker with a valid student account can view administrative menus and potentially modify sensitive academic data or user accounts, leading to unauthorized changes in student records.

Technical details

An improper authorization vulnerability exists in dashboard.php and dashboard_page/admin_page.php of the CollegeManagementSystem. The application fails to validate the user's role before including administrative components, relying solely on the presence of the $UserAuthData variable. A remote authenticated attacker (e.g., a student) can manipulate the UserAuthData argument or simply log in to gain access to the administrative interface. This allows unauthorized access to management functions such as user administration, course management, and data uploads. As of the advisory date, no patch has been released by the vendor.

Affected products

  • tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3

Timeline

  • 2026-05-18: disclosed: Issue reported on GitHub by researcher
  • 2026-06-05: advisory: NVD/VulDB advisory published

References

Related threats