Sceawere
Vulnerability Detail
CVE-2026-100897UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
StudentInfo Authorization Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 6h ago
- Vendor
- fuzui
- Product
- StudentInfo
- Attack Type
- Authorization Bypass
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability has been detected in fuzui StudentInfo up to fcc42a639ec7cef620651bfd0f07ebb660529e3f. The impacted element is an unknown function of the file /StudentInfo/StudentHandler/moditypasswordstu of the component Password Change Endpoint. Such manipulation of the argument sid/tid leads to authorization bypass. The attack can be executed remotely. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-09-28T02:17:19.800Z",
"pubdate": "2026-09-28T02:17:19.800Z",
"executiveSummary": "A critical authorization bypass vulnerability has been identified in the fuzui StudentInfo component, specifically within the /StudentInfo/StudentHandler/moditypasswordstu endpoint.\nThe vulnerability allows remote, unauthenticated attackers to manipulate the 'sid' or 'tid' arguments to bypass intended access control mechanisms.\nBy successfully exploiting this flaw, an attacker can perform unauthorized password modification, potentially leading to full account takeover of arbitrary user accounts.\nThe vulnerability affects all versions of StudentInfo up to commit fcc42a639ec7cef620651bfd0f07ebb660529e3f.\nDue to the nature of the vulnerability occurring at the authentication/authorization boundary, it presents a significant risk to the integrity and confidentiality of student account data.\nThe vendor has remained unresponsive to disclosure attempts, leaving the software in an unpatched state.\nThis flaw is remotely exploitable and does not require complex prerequisites, making it a high-priority concern for deployments utilizing this codebase.",
"technicalDetails": "The vulnerability resides in the /StudentInfo/StudentHandler/moditypasswordstu file, which handles password change requests for the StudentInfo application.\nThe root cause of this security flaw is an Insecure Direct Object Reference (IDOR) or a logic error in the authorization layer where user-supplied identifiers ('sid' for student ID or 'tid' for teacher/target ID) are processed without sufficient server-side validation of the requester's identity.\nIn a standard secure implementation, the server should derive the identity of the user requesting a password change from a secure, server-side session object or a cryptographically verified token.\nHowever, in the affected version, the application trustingly relies on the 'sid' or 'tid' parameters provided in the HTTP request body or query string to determine which account's credentials should be modified.\nAn attacker can exploit this by intercepting a legitimate password change request or crafting a malicious HTTP request that directs the application to update the password for an arbitrary user identifier.\nBecause the system fails to verify that the session owner matches the 'sid'/'tid' being modified, the application effectively delegates access control decisions to the client-side input.\nThe attack flow proceeds as follows: 1) The attacker initiates an HTTP request to /StudentInfo/StudentHandler/moditypasswordstu. 2) The attacker injects the target victim's 'sid' or 'tid' into the respective argument field. 3) The backend application processes the request, fails to perform an authorization check against the requester's session, and proceeds to overwrite the password for the specified target account in the database.\nThis allows for an unauthorized password reset, granting the attacker access to the compromised account without requiring the original password or authorization from the legitimate account owner.\nThe impact is total loss of account integrity, as attackers can gain persistent, unauthorized access to sensitive student or faculty information stored within the StudentInfo system.\nThis vulnerability is reachable over the network and does not require the attacker to have pre-existing privileges, as the endpoint itself is exposed in a manner that permits unauthenticated manipulation of the target identifier parameters."
}