CVE-2026-11474

A security flaw has been discovered in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected is an unknown function of the file service/RegisterService.php of the component Registration Endpoint. Performing a manipulation of the argument stimg results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
Configurations

No configuration.

History

23 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Una falla de seguridad ha sido descubierta en el sistema de gestión de estudiantes Kushan2k hasta f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Afecta a una función desconocida del archivo service/RegisterService.PHP del componente Registration Endpoint. La manipulación del argumento stimg resulta en una carga sin restricciones. El ataque puede ser iniciado remotamente. El exploit ha sido publicado y puede ser utilizado para ataques. Este producto utiliza un modelo de lanzamiento continuo para entregar actualizaciones continuas. Como resultado, la información de versión específica para las versiones afectadas o actualizadas no está disponible. El proyecto fue informado del problema tempranamente a través de un informe de incidencia pero aún no ha respondido.

08 Jun 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 01:16

Updated : 2026-07-23 07:10


NVD link : CVE-2026-11474

Mitre link : CVE-2026-11474

CVE.ORG link : CVE-2026-11474


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type