Executive brief
A security flaw exists in the Kushan2k Student Management System, a tool used for managing educational records. An unauthorized person can bypass security checks to modify administrator profile information, such as email addresses and passwords. This could allow an attacker to take over administrative accounts, lock out legitimate users, or gain full control over the system and its data.
Technical details
The 'edit-admin' function in 'controllers/AdminController.php' fails to implement session-based authentication checks (e.g., verifying $_SESSION['isadmin']). This allows unauthenticated remote attackers to trigger administrative profile updates via POST requests. Additionally, the 'config/User.php' component constructs SQL queries using direct string concatenation of user-supplied parameters like 'id' and 'email', introducing a SQL injection vulnerability. An attacker can exploit these combined issues to modify administrator credentials or execute arbitrary SQL commands to compromise the database. As of the advisory date, the vendor has not responded to the issue report.
Affected products
- Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a
Timeline
- 2026-05-20: disclosed: Issue reported on GitHub repository
- 2026-06-08: advisory: CVE published by VulDB/NVD