Vulnerability Description
A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the component Bulk Import. This manipulation of the argument File causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Munyweki | Student Result Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/Shaon-Xis/SRMS-1.0---Unauthenticated-SMTP-Hijacking-to-AccounExploitMitigationThird Party Advisory
- https://vuldb.com/?ctiid.347366Permissions RequiredVDB Entry
- https://vuldb.com/?id.347366Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.756135Third Party AdvisoryVDB Entry
- https://www.sourcecodester.com/Product
FAQ
What is CVE-2026-2983?
CVE-2026-2983 is a vulnerability with a CVSS score of 7.3 (HIGH). A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the component Bulk Import...
How severe is CVE-2026-2983?
CVE-2026-2983 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-2983?
Check the references section above for vendor advisories and patch information. Affected products include: Munyweki Student Result Management System.