CVE-2026-97648: ningzichun student-management-system cross-site request forgery
A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function. Performing a manipulation results in cross-site request forgery. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be initiated remotely and requires user interaction, consistent with a victim being induced to perform a request. No attacker privileges are required.
Is public exploit information available?
Yes. The available data states that an exploit is public and may be used.
Which versions are known to be affected?
The issue affects ningzichun student-management-system through commit 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. No fixed version or remediation commit is provided.
What is known about vendor response?
The project was notified early through an issue report, but had not responded as of the reported information.