PatchSiren cyber security CVE debrief
CVE-2026-5671 Cyber-III CVE debrief
A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Impacted is an unknown function of the file /admin/class%20schedule/delete_batch.php of the component Class Schedule Deletion Endpoint. Executing a manipulation of the argument batch can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.
- Vendor
- Cyber-III
- Product
- Student-Management-System
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
This vulnerability affects Cyber-III Student-Management-System, specifically the Class Schedule Deletion Endpoint. Users of this system should be aware of the potential for cross-site scripting attacks and take necessary precautions.
Technical summary
The vulnerability is a cross-site scripting (XSS) issue in the Cyber-III Student-Management-System, specifically in the /admin/class schedule/delete_batch.php file. An attacker can manipulate the 'batch' argument to inject malicious code, which can be executed on the client-side. The vulnerability has a CVSS score of 2.1 and a severity of LOW. This issue arises from inadequate input validation and sanitization in the Class Schedule Deletion Endpoint, allowing for potential remote attacks. Users of this system should be aware of the potential for cross-site scripting attacks and take necessary precautions to protect against exploitation.
Defensive priority
The defensive priority for this vulnerability is moderate. While the CVSS score is LOW, the vulnerability is still a potential entry point for attackers, and cross-site scripting attacks can have significant consequences.
Recommended defensive actions
- Verify the system's configuration and ensure that the latest version is being used.
- Implement input validation and sanitization for user-supplied data.
- Use a web application firewall (WAF) to detect and prevent cross-site scripting attacks.
- Monitor the system for suspicious activity and implement incident response plans.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability was publicly disclosed, and the project was informed of the problem early through an issue report but has not responded yet. The CVE record was published on 2026-04-06T18:16:45.933Z and was last modified on 2026-07-24T09:10:00.153Z.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T18:16:45.933Z and has not been modified since then.