PT-2026-30195 · Projectsandprograms · School Management System

Sudosme

·

Published

2026-04-03

·

Updated

2026-04-03

·

CVE-2026-5472

CVSS v2.0

6.5

Medium

AV:N/AC:L/Au:S/C:P/I:P/A:P
A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. The affected element is an unknown function of the file /admin panel/settings.php of the component Profile Picture Handler. This manipulation of the argument File causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.

Exploit

Fix

Unrestricted File Upload

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-5472

Affected Products

School Management System