Description
A security vulnerability has been detected in fuzui StudentInfo up to fcc42a639ec7cef620651bfd0f07ebb660529e3f. The impacted element is an unknown function of the file /StudentInfo/StudentHandler/moditypasswordstu of the component Password Change Endpoint. Such manipulation of the argument sid/tid leads to authorization bypass. The attack can be executed remotely. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Authorization Bypass
Action: Assess Impact
AI Analysis

Impact

The vulnerability resides in the password change endpoint of fuzui StudentInfo. By manipulating the sid/tid arguments sent to the /StudentInfo/StudentHandler/moditypasswordstu route, an attacker can bypass normal authorization checks. This allows an unauthorized user to change another user’s password, effectively granting that user access to the affected account. The weakness corresponds to improper authorization and user‑controlled key flaws, as identified by CWE‑285 and CWE‑639. With a CVSS score of 5.1, the impact is moderate but could enable credential compromise and further lateral movement within the system.

Affected Systems

The affected product is fuzui StudentInfo. All releases up to the commit fcc42a639ec7cef620651bfd0f07ebb660529e3f are vulnerable. Because the product follows a rolling release model, specific version numbers are not available and updates may be introduced without a formal version tag. The product’s endpoint is exposed at /StudentInfo/StudentHandler/moditypasswordstu and receives remote requests from clients that identify themselves by sid or tid parameters.

Risk and Exploitability

An attacker can trigger the bypass remotely by sending crafted HTTP requests that adjust the sid/tid values. The exploit does not require privileged credentials or local code execution, so it can be performed from outside the network. The CVSS score of 5.1 indicates a medium severity, and the lack of an EPSS score means the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, but the absence of a vendor response leaves the issue open until a patch is released. Until then, organizations should treat the vulnerability as a potential medium‑risk exposure that could lead to unauthorized account takeover if not mitigated.

Generated by OpenCVE AI on September 28, 2026 at 03:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Implement temporary access restrictions on the password change endpoint, for example by blocking or rate‑limiting requests from untrusted IP ranges that are not authorized to perform password changes.
  • Enable multi‑factor authentication for all user accounts so that a compromised or arbitrarily changed password cannot be used without the second factor.
  • Continuously monitor authentication logs and password change events for abnormal activity, and set alerts for potential unauthorized changes.

Generated by OpenCVE AI on September 28, 2026 at 03:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in fuzui StudentInfo up to fcc42a639ec7cef620651bfd0f07ebb660529e3f. The impacted element is an unknown function of the file /StudentInfo/StudentHandler/moditypasswordstu of the component Password Change Endpoint. Such manipulation of the argument sid/tid leads to authorization bypass. The attack can be executed remotely. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
Title fuzui StudentInfo Password Change Endpoint moditypasswordstu authorization
First Time appeared Fuzui
Fuzui studentinfo
Weaknesses CWE-285
CWE-639
CPEs cpe:2.3:a:fuzui:studentinfo:*:*:*:*:*:*:*:*
Vendors & Products Fuzui
Fuzui studentinfo
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:C'}

cvssV3_0

{'score': 5.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:X/RL:X/RC:C'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:X/RL:X/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Fuzui Studentinfo
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T01:45:08.084Z

Reserved: 2026-09-27T08:34:33.019Z

Link: CVE-2026-100897

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T02:17:19.800

Modified: 2026-09-28T02:17:19.800

Link: CVE-2026-100897

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T04:00:15Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key