A vulnerability was found in the Student Management System, affecting the session_start function in login.php, which allows for session fixation. The attack can be launched remotely. This product does not use versioning, making information about affected and unaffected releases unavailable. Defenders should assess their exposure and verify the presence of this vulnerability. The CVE record and NVD entry p [truncated]
A vulnerability was found in the ningzichun Student Management System, specifically in the Backup Handler component. The vulnerability leads to information disclosure and can be initiated remotely. The project has been informed but has not responded yet. The vulnerability has a CVSS score of 5.5, indicating a medium severity level. Defenders should prioritize verifying exposure and assessing potential imp [truncated]