Description
A vulnerability has been found in SourceCodester Student Result Management System 1.0. The affected element is an unknown function of the file /srms/script/admin/core/update_smtp.php. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2026-02-21: | Advisory disclosed |
| 2026-02-21: | VulDB entry created |
| 2026-02-21: | VulDB entry last update |
Credits
yan1451 (VulDB User)
References
vuldb.com/?id.347310 (VDB-347310 | SourceCodester Student Result Management System update_smtp.php access control)
vuldb.com/?ctiid.347310 (VDB-347310 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.755345 (Submit #755345 | SourceCodester Student Result Management System 1.0 Improper Access Controls)
github.com/...thenticated-SMTP-Hijacking-to-Account-Takeover
www.sourcecodester.com/