CVE-2026-10777
Authentication Bypass in ealpha072 Student-Management-System
Publication date: 2026-06-03
Last updated on: 2026-06-03
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-287 | When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the ealpha072 Student-Management-System, specifically in the admin/config.php file of the Administrative Backend component. It allows an attacker to perform improper authentication by manipulating some unknown functionality within that file. The attack can be executed remotely, and an exploit for this vulnerability is publicly available.
How can this vulnerability impact me? :
The vulnerability can lead to improper authentication, potentially allowing unauthorized remote attackers to gain access to administrative functions of the system. This could result in unauthorized access to sensitive student management data or administrative controls.