Impact
The vulnerability occurs in the Student Management System’s login.php when the session_start function allows an attacker to fixate a session identifier. By manipulating the session cookie or request parameters, an adversary can force the application to use a session ID chosen by the attacker. Once the user logs in, the attacker already knows that session ID and can hijack the authenticated session, thus gaining unauthorized access to protected resources. This flaw directly leads to a possible escalation of privileges and unauthorized data access, meeting CWE‑384 criteria for session fixation.
Affected Systems
The affected product is the ningzichun Student Management System. No specific release or version numbers are publicly available; the issue applies to any installation that uses the vulnerable commit prior to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Both web and API interfaces that invoke session_start in login.php are impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The exploit is described as publicly available and can be launched remotely, suggesting that attackers can target any exposed instance without local code execution. The EPSS score is not available, so the current exploitation probability is uncertain, and the vulnerability is not listed in CISA’s KEV catalog. The remote nature of the attack combined with the absence of an availability impact, but with clear confidentiality and integrity consequences, makes this flaw a moderate but meaningful risk for deployed systems.
OpenCVE Enrichment