Description
A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connection. This manipulation causes hard-coded credentials. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-08
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized database access
Action: Assess Impact
AI Analysis

Impact

The vulnerability resides in the database.php file of the Student Management System and allows the function mysqli_connect to use hard‑coded credentials. This flaw is a classic example of CWE-259 and CWE-798, resulting in an attacker being able to remotely create a database connection using the stored username and password and thereby read, modify or delete sensitive data in the MySQL database. The input suggests that exploitation is possible from outside the system and that the issue has been made public, increasing the risk of immediate attacks.

Affected Systems

The affected product is ningzichun Student Management System, with the vulnerability present in all releases up to the commit identified as 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. No specific version numbers are available due to the continuous rolling release model used by the project.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate impact potential, while the EPSS score of 0.00278 (0.278%) indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote because the description explicitly states that the attack may be initiated remotely and the exploit has been publicly disclosed. Because the flaw relies on hard‑coded credentials, the likelihood of successful exploitation depends on whether the database is exposed and whether the default credentials are known or easily guessable.

Generated by OpenCVE AI on September 9, 2026 at 22:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace the hard‑coded database credentials in config/database.php with secure, environment‑based configuration or an external secrets store.
  • Apply any available updates from the project's repository that remove or fix the hard‑coded credentials; if no update is available, revert the changes and remove the file from the web root.
  • Restrict database access using firewall rules or local network isolation so that only trusted application instances can connect, thereby reducing the attack surface.

Generated by OpenCVE AI on September 9, 2026 at 22:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connection. This manipulation causes hard-coded credentials. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
Title ningzichun Student Management System Database Connection database.php mysqli_connect hard-coded credentials
First Time appeared Ningzichun
Ningzichun student Management System
Weaknesses CWE-259
CWE-798
CPEs cpe:2.3:a:ningzichun:student_management_system:*:*:*:*:*:*:*:*
Vendors & Products Ningzichun
Ningzichun student Management System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Ningzichun Student Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-08T18:11:42.177Z

Reserved: 2026-09-08T09:36:15.259Z

Link: CVE-2026-86673

cve-icon Vulnrichment

Updated: 2026-09-08T18:11:38.581Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T18:21:17.727

Modified: 2026-09-08T19:20:16.413

Link: CVE-2026-86673

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:30:02Z

Weaknesses
  • CWE-259

    Use of Hard-coded Password

  • CWE-798

    Use of Hard-coded Credentials