CVE-2026-2983

HIGH

Student Result Management System 1.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the component Bulk Import. This manipulation of the argument File causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

References (5)

Core 5
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.347366
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.347366
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.756135
Various Sources product
https://www.sourcecodester.com/

Scores

CVSS v3 7.3
EPSS 0.0041
EPSS Percentile 32.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-266 CWE-284
Status published
Products (1)
munyweki/student_result_management_system 1.0
Published Feb 23, 2026
Tracked Since Feb 23, 2026