Impact
A flaw in the Password Handler of sambitraj Student Management System allows an attacker to manipulate the Password argument so that credentials are stored in cleartext in the aca.sql file. This flaw represents a CWE-310 and CWE-312 weakness, resulting in the compromise of user passwords and any associated sensitive data. The vulnerability permits remote exploitation, and an exploit package has already been published.
Affected Systems
The affected product is sambitraj Student Management System, version up to commit 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Because the project uses a rolling release model, specific downstream versions are not listed and additional updates may also contain the flaw.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity, and the EPSS score is unavailable. KEV does not list the vulnerability, but the existence of a publicly available exploit and the remote execution vector increase its practical risk. The attacker can obtain stored passwords in plaintext, enabling credential theft, impersonation, and potential escalation of privileges within the system.
OpenCVE Enrichment