Junglewise Threat Intelligence

CVE-2026-11533: imvks786 Student Management System improper authorization in see.php

CVE-2026-11533 · Severity: medium · CVSS 5.4 · Published 2026-06-08

Technologies: Imvks786 Student Management System.

Executive brief

A vulnerability exists in the imvks786 Student Management System, a web application used for managing student records. An authorized user with low-level permissions can bypass security checks to delete student records they should not have access to modify. This could lead to unauthorized data loss and disruption of school administrative operations.

Technical details

An improper authorization vulnerability (CWE-285/CWE-266) exists in see.php within the imvks786 student_management_system up to commit 9599b56. The application processes the 'del' GET parameter and executes a SQL DELETE query before verifying the user's permission level. While the code later checks the 'Permission' field from the database, this check only affects the displayed message and does not prevent the initial destructive action. A remote attacker with basic authenticated access (e.g., 'VIEW' permissions) can delete any student record by crafting a specific GET request. As of the advisory date, the project has not responded to the issue report.

Affected products

  • imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46

Timeline

  • 2026-05-25: disclosed: Issue reported on GitHub repository
  • 2026-06-08: advisory: NVD/VulDB publication

References