Authorization Bypass in fuzui StudentInfo Product
CVE-2026-100897

5.1MEDIUM

Key Information:

Vendor

Fuzui

Vendor
CVE Published:
28 September 2026

What is CVE-2026-100897?

A security vulnerability exists in the fuzui StudentInfo product, specifically in its Password Change Endpoint. The issue arises from a flaw in an unknown function within the /StudentInfo/StudentHandler/moditypasswordstu file, which allows attackers to exploit the sid/tid argument for authorization bypass. This vulnerability can be executed remotely, posing significant risks. Despite early notification, the vendor has not responded concerning this vulnerability, leaving users potentially exposed to unauthorized access.

Affected Version(s)

StudentInfo fcc42a639ec7cef620651bfd0f07ebb660529e3f

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

pusa1 (VulDB User)
VulDB CNA Team
.