← Terug naar overzicht

A vulnerability has been identified in Soarkey StudentManagement (学生信息管理系统) affecting versions up to commit e08f7f1d5015af407aa4cca0ada3dea189b4937e. The flaw resides in the AdminDao.doGet function within the file code/src/service/AdminDao.java, part of the Administrative Servlet component. By manipulating the 'action' argument, an attacker can achieve authorization bypass remotely. A public exploit is already available, increasing the risk of active exploitation. The project maintainer was notified via a GitHub issue report but has not responded. This is a remotely exploitable, publicly disclosed vulnerability with no known patch or vendor acknowledgment at the time of reporting.

Affected products

  • Soarkey StudentManagement
  • 学生信息管理系统

Related CVE's

  • CVE-2026-82621

Categories

  • Identity & Access
  • Web Technologies
  • Zero-Day Vulnerabilities