Security Advisory

CVE-2026-86673

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-08 18:00:08
Last updated 2026-09-08 18:11:42
Assigner VulDB
CVSS score 7.5
State PUBLISHED

Description

A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connection. This manipulation causes hard-coded credentials. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.