Authorization Bypass in fuzui StudentInfo Product
CVE-2026-100897
5.1MEDIUM
What is CVE-2026-100897?
A security vulnerability exists in the fuzui StudentInfo product, specifically in its Password Change Endpoint. The issue arises from a flaw in an unknown function within the /StudentInfo/StudentHandler/moditypasswordstu file, which allows attackers to exploit the sid/tid argument for authorization bypass. This vulnerability can be executed remotely, posing significant risks. Despite early notification, the vendor has not responded concerning this vulnerability, leaving users potentially exposed to unauthorized access.
Affected Version(s)
StudentInfo fcc42a639ec7cef620651bfd0f07ebb660529e3f
