Impact
A vulnerability in sambitraj Student-Management-System allows attacker to force the use of a default password by manipulating the aca.sql file. Because the application does not validate or override this value, an attacker can log in with predictable credentials, thereby gaining unauthorized access to the system. The flaw falls under CWE-1393, Improper Use of Default Credentials, and can lead to full compromise of the application’s data and functionality.
Affected Systems
The affected product is sambitraj Student‑Management‑System. Version information is not provided due to a rolling‑release delivery model, but the issue exists in the codebase up to commit 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. All releases derived from this commit sequence are potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the lack of an EPSS score means the exploit probability is unknown at this time. Because the exploit is public and can be launched remotely by submitting a request that triggers the default password, the risk to organizations running this system without mitigation is significant. The vulnerability is not listed in the CISA KEV catalog, but that does not preclude its practical impact. Attacker effort is minimal, requiring only knowledge of the application’s default credentials and the ability to reach the login endpoint.
OpenCVE Enrichment