Junglewise Threat Intelligence

CVE-2026-11532: imvks786 student_management_system improper access control in Student Record Handler

CVE-2026-11532 · Severity: medium · CVSS 6.3 · Published 2026-06-08

Technologies: Imvks786 Student Management System.

Executive brief

A vulnerability in the imvks786 Student Management System allows users with low-level 'view-only' permissions to perform administrative actions. This software is used to manage student records, and an exploit allows unauthorized users to add or delete student data. This could lead to the loss of accurate student records or the unauthorized modification of sensitive educational information.

Technical details

An improper access control vulnerability (CWE-284/CWE-266) exists in the Student Record Handler component of the imvks786 student_management_system. The application relies on client-side UI restrictions (hiding buttons) rather than server-side validation to enforce role-based access control. Specifically, the 'add.php' and 'see.php' endpoints only verify that a user is logged in, failing to check if the user possesses 'ADMIN' or 'EDIT' privileges. A remote authenticated attacker with 'VIEW' permissions can bypass these restrictions by sending direct POST or GET requests to these endpoints to add or delete student records. As of the advisory date, no patch has been released by the maintainer.

Affected products

  • imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46

Timeline

  • 2026-05-25: disclosed: Issue reported to the project maintainer via GitHub
  • 2026-06-08: advisory: CVE published by VulDB

References