Description
A flaw has been found in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This impacts an unknown function of the file aca.sql of the component Password Handler. Executing a manipulation of the argument Password can lead to cleartext storage of sensitive information. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable.
Published: 2026-08-31
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Password Handler of sambitraj Student Management System allows an attacker to manipulate the Password argument so that credentials are stored in cleartext in the aca.sql file. This flaw represents a CWE-310 and CWE-312 weakness, resulting in the compromise of user passwords and any associated sensitive data. The vulnerability permits remote exploitation, and an exploit package has already been published.

Affected Systems

The affected product is sambitraj Student Management System, version up to commit 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Because the project uses a rolling release model, specific downstream versions are not listed and additional updates may also contain the flaw.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity, and the EPSS score is unavailable. KEV does not list the vulnerability, but the existence of a publicly available exploit and the remote execution vector increase its practical risk. The attacker can obtain stored passwords in plaintext, enabling credential theft, impersonation, and potential escalation of privileges within the system.

Generated by OpenCVE AI on August 31, 2026 at 16:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Student Management System to a current release that encrypts passwords before storage (review the project roadmap for a fix after commit 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5).
  • Replace or modify the aca.sql password handling logic to hash and salt passwords with a strong algorithm such as bcrypt or Argon2, ensuring that no plain‑text credentials are written to storage.
  • Restrict remote access to the endpoint that processes the Password argument, enforcing proper authentication and authorization controls to prevent unauthorized manipulation of the password field.

Generated by OpenCVE AI on August 31, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Sambitraj student-management-system
Vendors & Products Sambitraj student-management-system

Mon, 31 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This impacts an unknown function of the file aca.sql of the component Password Handler. Executing a manipulation of the argument Password can lead to cleartext storage of sensitive information. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable.
Title sambitraj Student Management System Password aca.sql cleartext storage
First Time appeared Sambitraj
Sambitraj student Management System
Weaknesses CWE-310
CWE-312
CPEs cpe:2.3:a:sambitraj:student_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sambitraj
Sambitraj student Management System
References
Metrics cvssV2_0

{'score': 3.3, 'vector': 'AV:N/AC:L/Au:M/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 2.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sambitraj Student-management-system Student Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T15:14:01.908Z

Reserved: 2026-08-30T17:56:19.012Z

Link: CVE-2026-82699

cve-icon Vulnrichment

Updated: 2026-08-31T15:13:35.482Z

cve-icon NVD

Status : Received

Published: 2026-08-31T14:17:27.170

Modified: 2026-08-31T16:19:18.693

Link: CVE-2026-82699

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T16:30:05Z

Weaknesses