Impact
The vulnerability resides in the password change endpoint of fuzui StudentInfo. By manipulating the sid/tid arguments sent to the /StudentInfo/StudentHandler/moditypasswordstu route, an attacker can bypass normal authorization checks. This allows an unauthorized user to change another user’s password, effectively granting that user access to the affected account. The weakness corresponds to improper authorization and user‑controlled key flaws, as identified by CWE‑285 and CWE‑639. With a CVSS score of 5.1, the impact is moderate but could enable credential compromise and further lateral movement within the system.
Affected Systems
The affected product is fuzui StudentInfo. All releases up to the commit fcc42a639ec7cef620651bfd0f07ebb660529e3f are vulnerable. Because the product follows a rolling release model, specific version numbers are not available and updates may be introduced without a formal version tag. The product’s endpoint is exposed at /StudentInfo/StudentHandler/moditypasswordstu and receives remote requests from clients that identify themselves by sid or tid parameters.
Risk and Exploitability
An attacker can trigger the bypass remotely by sending crafted HTTP requests that adjust the sid/tid values. The exploit does not require privileged credentials or local code execution, so it can be performed from outside the network. The CVSS score of 5.1 indicates a medium severity, and the lack of an EPSS score means the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, but the absence of a vendor response leaves the issue open until a patch is released. Until then, organizations should treat the vulnerability as a potential medium‑risk exposure that could lead to unauthorized account takeover if not mitigated.
OpenCVE Enrichment