Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 28 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in fuzui StudentInfo up to fcc42a639ec7cef620651bfd0f07ebb660529e3f. The impacted element is an unknown function of the file /StudentInfo/StudentHandler/moditypasswordstu of the component Password Change Endpoint. Such manipulation of the argument sid/tid leads to authorization bypass. The attack can be executed remotely. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | fuzui StudentInfo Password Change Endpoint moditypasswordstu authorization | |
| First Time appeared |
Fuzui
Fuzui studentinfo |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:fuzui:studentinfo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fuzui
Fuzui studentinfo |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-28T01:45:08.084Z
Reserved: 2026-09-27T08:34:33.019Z
Link: CVE-2026-100897
No data.
Status : Received
Published: 2026-09-28T02:17:19.800
Modified: 2026-09-28T02:17:19.800
Link: CVE-2026-100897
No data.
OpenCVE Enrichment
Updated: 2026-09-28T04:00:15Z