PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-11533 imvks786 CVE debrief

A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this vulnerability is an unknown functionality of the file /see.php of the component Student Deletion Endpoint. The manipulation of the argument del leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

Vendor
imvks786
Product
student_management_system
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-08
Original CVE updated
2026-06-09
Advisory published
2026-06-08
Advisory updated
2026-06-09

Who should care

Users of imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46

Technical summary

The vulnerability is caused by improper authorization in the /see.php file of the Student Deletion Endpoint. The manipulation of the argument del can lead to unauthorized actions.

Defensive priority

LOW

Recommended defensive actions

  • Apply patches or updates as soon as they become available
  • Restrict access to the /see.php file
  • Monitor for suspicious activity

Evidence notes

The vulnerability has been publicly disclosed and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Official resources

CVE-2026-11533 was published on 2026-06-08T17:16:40.563Z and modified on 2026-06-09T01:34:33.987Z.