Description
A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is the function session_start of the file login.php. The manipulation results in session fixiation. The attack can be launched remotely. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Session Hijack
Action: Apply Patch
AI Analysis

Impact

The vulnerability occurs in the Student Management System’s login.php when the session_start function allows an attacker to fixate a session identifier. By manipulating the session cookie or request parameters, an adversary can force the application to use a session ID chosen by the attacker. Once the user logs in, the attacker already knows that session ID and can hijack the authenticated session, thus gaining unauthorized access to protected resources. This flaw directly leads to a possible escalation of privileges and unauthorized data access, meeting CWE‑384 criteria for session fixation.

Affected Systems

The affected product is the ningzichun Student Management System. No specific release or version numbers are publicly available; the issue applies to any installation that uses the vulnerable commit prior to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Both web and API interfaces that invoke session_start in login.php are impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The exploit is described as publicly available and can be launched remotely, suggesting that attackers can target any exposed instance without local code execution. The EPSS score is not available, so the current exploitation probability is uncertain, and the vulnerability is not listed in CISA’s KEV catalog. The remote nature of the attack combined with the absence of an availability impact, but with clear confidentiality and integrity consequences, makes this flaw a moderate but meaningful risk for deployed systems.

Generated by OpenCVE AI on September 9, 2026 at 14:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Student Management System to a commit that removes session fixation by regenerating the session ID after a successful login.
  • Modify the login.php script to call session_regenerate_id(true) immediately after authentication, thereby invalidating any pre‑existing session identifier.
  • Set PHP session configuration options such as session.use_strict_mode=1 and session.cookie_httponly=1 to mitigate session fixation attempts.

Generated by OpenCVE AI on September 9, 2026 at 14:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is the function session_start of the file login.php. The manipulation results in session fixiation. The attack can be launched remotely. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Title ningzichun Student Management System login.php session_start session fixiation
First Time appeared Ningzichun
Ningzichun student Management System
Weaknesses CWE-384
CPEs cpe:2.3:a:ningzichun:student_management_system:*:*:*:*:*:*:*:*
Vendors & Products Ningzichun
Ningzichun student Management System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Ningzichun Student Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-11T20:34:19.388Z

Reserved: 2026-09-08T09:36:18.424Z

Link: CVE-2026-86674

cve-icon Vulnrichment

Updated: 2026-09-11T20:02:46.193Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T19:20:16.963

Modified: 2026-09-11T21:17:48.770

Link: CVE-2026-86674

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:30:02Z

Weaknesses