Home

Description

A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student Management Handler. Executing a manipulation can lead to improper access controls. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED Reserved 2026-05-25 | Published 2026-05-26 | Updated 2026-05-26 | Assigner VulDB




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
HIGH: 7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
HIGH: 7.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
7.5AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR

Problem types

Improper Access Controls

Incorrect Privilege Assignment

Product status

9abd69448c66555d434755e6bd0b099a8527a0a9
affected

9157e0c28b177fdbe69cf76e878eca365fedbf5f
affected

f2e07d2ecd007fa1429f0444510ad95a8d0d7c73
affected

Timeline

2026-05-25:Advisory disclosed
2026-05-25:VulDB entry created
2026-05-25:VulDB entry last update

Credits

Wwen (VulDB User) reporter

VulDB CNA Team coordinator

References

vuldb.com/vuln/365537 (VDB-365537 | hemant6488 CodeIgniter-StudentManagementSystem Student Management addStudentView access control) vdb-entry

vuldb.com/vuln/365537/cti (VDB-365537 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/submit/814277 (Submit #814277 | hemant6488 CodeIgniter-StudentManagementSystem 1.0 Unauthenticated Access) third-party-advisory

github.com/...8/CodeIgniter-StudentManagementSystem/issues/5 exploit issue-tracking

github.com/hemant6488/CodeIgniter-StudentManagementSystem/ product

cve.org (CVE-2026-9517)

nvd.nist.gov (CVE-2026-9517)

Download JSON