CVE-2026-2938: SourceCodester Student Result Management System update_smtp.php access control
A vulnerability has been found in SourceCodester Student Result Management System 1.0. The affected element is an unknown function of the file /srms/script/admin/core/updatesmtp.php. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2938?
CVE-2026-2938 has a moderate severity rating due to improper access control vulnerabilities.
How do I fix CVE-2026-2938?
To fix CVE-2026-2938, update the SourceCodester Student Result Management System to the latest version that includes security patches.
What systems are affected by CVE-2026-2938?
CVE-2026-2938 affects SourceCodester Student Result Management System version 1.0.
What type of vulnerability is CVE-2026-2938?
CVE-2026-2938 is classified as an improper access control vulnerability.
When was CVE-2026-2938 disclosed?
CVE-2026-2938 was disclosed in the year 2026.