Description
A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown function of the file aca.sql. Performing a manipulation results in use of default password. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-08-31
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote authentication bypass using default credentials
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in sambitraj Student-Management-System allows attacker to force the use of a default password by manipulating the aca.sql file. Because the application does not validate or override this value, an attacker can log in with predictable credentials, thereby gaining unauthorized access to the system. The flaw falls under CWE-1393, Improper Use of Default Credentials, and can lead to full compromise of the application’s data and functionality.

Affected Systems

The affected product is sambitraj Student‑Management‑System. Version information is not provided due to a rolling‑release delivery model, but the issue exists in the codebase up to commit 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. All releases derived from this commit sequence are potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the lack of an EPSS score means the exploit probability is unknown at this time. Because the exploit is public and can be launched remotely by submitting a request that triggers the default password, the risk to organizations running this system without mitigation is significant. The vulnerability is not listed in the CISA KEV catalog, but that does not preclude its practical impact. Attacker effort is minimal, requiring only knowledge of the application’s default credentials and the ability to reach the login endpoint.

Generated by OpenCVE AI on August 31, 2026 at 14:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Student-Management-System to the latest commit that addresses the aca.sql default password issue or apply an official vendor patch once released.
  • If a patch is not available, immediately change the default password in the database and enforce a secure password policy for all accounts.
  • Configure the application to force a password change on first login and disable all default or pre‑set credentials.
  • Restrict network access to the application by firewalling or VPN to limit exposure to potential attackers.

Generated by OpenCVE AI on August 31, 2026 at 14:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown function of the file aca.sql. Performing a manipulation results in use of default password. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.
Title sambitraj Student-Management-System aca.sql default password
First Time appeared Sambitraj
Sambitraj student-management-system
Weaknesses CWE-1393
CPEs cpe:2.3:a:sambitraj:student-management-system:*:*:*:*:*:*:*:*
Vendors & Products Sambitraj
Sambitraj student-management-system
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sambitraj Student-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T22:03:06.504Z

Reserved: 2026-08-30T17:56:14.849Z

Link: CVE-2026-82698

cve-icon Vulnrichment

Updated: 2026-08-31T21:51:45.597Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T14:17:26.980

Modified: 2026-08-31T22:17:30.343

Link: CVE-2026-82698

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T15:45:16Z

Weaknesses