CVE-2026-86673: Ningzichun Student Management System
High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connection. This manipulation causes hard-coded credentials. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
Affected products
- Ningzichun Student Management System
Published 2026-09-08. Last modified 2026-09-08.