Impact
A flaw in the registration workflow allows an attacker to manipulate the level argument when registering a user. By modifying this argument the attacker can assign themselves or others higher privileges than intended. The vulnerability is a form of improper privilege escalation, which is reflected by the listed weaknesses CWE-266 and CWE-269. This can lead to accessing or modifying sensitive student data, changing grades, or performing administrative tasks.
Affected Systems
The affected product is Soarkey StudentManagement, a web‑based student management system. The specific function impacted is RegisterServlet.doPost in the register.html component. No versioning information is present, so all releases are potentially affected so system an update is released.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the exploit is publicly available and can be launched remotely, though the EPSS score is unknown. The vulnerability is not listed in CISA’s KEV catalog. The exploit path involves remotely submitting a crafted registration request that includes a manipulated level value, suggesting that basic network exposure is sufficient to launch the attack. Given the lack of formal patch and public availability of the exploit, administrators should treat this as a tangible risk and attempt to mitigate it promptly.
OpenCVE Enrichment