Impact
The Student Management System includes a Backup Handler component that processes an example.7z file. An unknown function within this file can be manipulated to expose sensitive information. The flaw allows a remote attacker to trigger the function and obtain data that should remain confidential, potentially compromising the application’s data confidentiality. The vulnerability falls under CWE‑200 and CWE‑284 classes.
Affected Systems
The affected vendor is ningzichun and the product is the Student Management System. No specific versions are identified because the project uses continuous delivery and rolling releases, so any build before the unknown commit 98760f5711cf6dc8b4adca53a9e207ca49b02ebf may be vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium risk for information disclosure. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can initiate the exploit remotely and, as the exploit has been publicly disclosed, it may already be in circulation. No vendor patch or advisory has been released, so the likelihood of exploitation in the wild remains uncertain but should be treated as a potential risk pending official resolution.
OpenCVE Enrichment