Description
A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the component Bulk Import. This manipulation of the argument File causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Published: 2026-02-23
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Improper Access Control
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is located in the Bulk Import feature of SourceCodester Student Result Management System 1.0, specifically the import_users.php handler. An attacker can manipulate the File argument to bypass built‑in access checks, enabling the upload of arbitrary files or the creation of user accounts without authentication. This weakness, based on CWE‑266 and CWE‑284, permits elevation of privileges and potential compromise of the system by injecting malicious code or unauthorized users.

Affected Systems

SourceCodester Student Result Management System 1.0, sold through SourceCodester. The affected component is the admin core script import_users.php. No other versions are listed; the only published version at the time of disclosure is 1.0.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. EPSS is listed as <1%, reflecting a low but nonzero likelihood that this flaw will be actively exploited. The vulnerability is not catalogued in CISA’s KEV list, and public exploit code is available on GitHub, implying that an attacker can launch a remote exploit without authentication. Because the access control is insufficient, the attack vector is likely through the web interface to the bulk import endpoint.

Generated by OpenCVE AI on April 17, 2026 at 16:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install any security update or patch released by SourceCodester for the Bulk Import module if available.
  • Disable the bulk import feature or restrict access so that only authenticated administrators can invoke import_users.php.
  • Enforce strict file upload validation: restrict allowed file types, limit size, store uploads outside the web root, and scan uploaded files for malicious content before processing.

Generated by OpenCVE AI on April 17, 2026 at 16:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 24 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Munyweki
Munyweki student Result Management System
CPEs cpe:2.3:a:munyweki:student_result_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Munyweki
Munyweki student Result Management System

Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester student Result Management System
Vendors & Products Sourcecodester
Sourcecodester student Result Management System

Mon, 23 Feb 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 10:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the component Bulk Import. This manipulation of the argument File causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Title SourceCodester Student Result Management System Bulk Import import_users.php access control
Weaknesses CWE-266
CWE-284
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Munyweki Student Result Management System
Sourcecodester Student Result Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T12:45:23.221Z

Reserved: 2026-02-22T16:42:13.541Z

Link: CVE-2026-2983

cve-icon Vulnrichment

Updated: 2026-02-23T12:45:15.775Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-23T10:16:58.757

Modified: 2026-02-24T18:32:54.093

Link: CVE-2026-2983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T16:30:05Z

Weaknesses