Impact
The vulnerability resides in the database.php file of the Student Management System and allows the function mysqli_connect to use hard‑coded credentials. This flaw is a classic example of CWE-259 and CWE-798, resulting in an attacker being able to remotely create a database connection using the stored username and password and thereby read, modify or delete sensitive data in the MySQL database. The input suggests that exploitation is possible from outside the system and that the issue has been made public, increasing the risk of immediate attacks.
Affected Systems
The affected product is ningzichun Student Management System, with the vulnerability present in all releases up to the commit identified as 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. No specific version numbers are available due to the continuous rolling release model used by the project.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate impact potential, while the EPSS score of 0.00278 (0.278%) indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote because the description explicitly states that the attack may be initiated remotely and the exploit has been publicly disclosed. Because the flaw relies on hard‑coded credentials, the likelihood of successful exploitation depends on whether the database is exposed and whether the default credentials are known or easily guessable.
OpenCVE Enrichment