PT-2026-45943 · Projectsandprograms · School Management System
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ProjectsAndPrograms school-management-system (affected versions not specified)
Description
The software uses predictable credentials by generating passwords for students and teachers based solely on the user's date of birth. Additionally, the application does not require users to change their password during the first login, which allows attackers to guess or derive valid credentials to gain unauthorized account access.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
School Management System