Description
A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-08
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The Student Management System includes a Backup Handler component that processes an example.7z file. An unknown function within this file can be manipulated to expose sensitive information. The flaw allows a remote attacker to trigger the function and obtain data that should remain confidential, potentially compromising the application’s data confidentiality. The vulnerability falls under CWE‑200 and CWE‑284 classes.

Affected Systems

The affected vendor is ningzichun and the product is the Student Management System. No specific versions are identified because the project uses continuous delivery and rolling releases, so any build before the unknown commit 98760f5711cf6dc8b4adca53a9e207ca49b02ebf may be vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium risk for information disclosure. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can initiate the exploit remotely and, as the exploit has been publicly disclosed, it may already be in circulation. No vendor patch or advisory has been released, so the likelihood of exploitation in the wild remains uncertain but should be treated as a potential risk pending official resolution.

Generated by OpenCVE AI on September 9, 2026 at 20:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any official patch or updated release from ningzichun once it becomes available.
  • Disable or remove the Backup Handler component or the example.7z file if it is not necessary for the system’s operation.
  • Restrict network access to the feature that triggers the vulnerable function to trusted hosts or internal network segments.
  • Monitor system logs for unexpected access to the Backup Handler and audit exploitation attempts.

Generated by OpenCVE AI on September 9, 2026 at 20:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Title ningzichun Student Management System Backup example.7z information disclosure
First Time appeared Ningzichun
Ningzichun student Management System
Weaknesses CWE-200
CWE-284
CPEs cpe:2.3:a:ningzichun:student_management_system:*:*:*:*:*:*:*:*
Vendors & Products Ningzichun
Ningzichun student Management System
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Ningzichun Student Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-11T20:53:17.420Z

Reserved: 2026-09-08T09:36:11.968Z

Link: CVE-2026-86672

cve-icon Vulnrichment

Updated: 2026-09-11T20:53:12.734Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T18:21:17.553

Modified: 2026-09-11T21:17:48.257

Link: CVE-2026-86672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-12T02:15:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control