PT-2026-45172 · Ousl · Brinarybrains School Student Management System

·

CVE-2026-10169

·

Published

2026-05-31

·

Updated

2026-05-31

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OUSL-GROUP-BrinaryBrains School Student Management System versions prior to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6
Description An issue exists in the Forgot Password Endpoint within the ajax forgot password() function of the application/controllers/Login.php file. Manipulation of the email argument allows for weak password recovery. This flaw can be exploited remotely, although it is characterized by high complexity and difficult exploitation.
Recommendations Update to a version later than 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. As a temporary workaround, restrict access to the ajax forgot password() function in the application/controllers/Login.php file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10169

Affected Products

Brinarybrains School Student Management System