PT-2026-36600 · Zyosoft · School App

Published

2026-05-02

·

Updated

2026-05-02

·

CVE-2026-7491

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions School App developed by Zyosoft (affected versions not specified)
Description An Insecure Direct Object Reference (IDOR) issue exists, where authenticated remote attackers can modify a specific parameter to read and modify data belonging to other users. IDOR is a type of access control flaw that occurs when an application uses user-supplied input to access objects directly.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-7491

Affected Products

School App