CVE-2026-2201

A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. This impacts the function addLeave of the file src/main/java/com/wdd/studentmanager/controller/LeaveController.java. The manipulation of the argument Reason for Leave leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The code repository of the project has not been active for many years.
References
Link Resource
https://vuldb.com/?ctiid.344904 Permissions Required VDB Entry
https://vuldb.com/?id.344904 Third Party Advisory VDB Entry
https://vuldb.com/?submit.750217 Third Party Advisory VDB Entry
https://www.yuque.com/clockw1se/lts9x9/mxgrzspnzmpxu7e7 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:zerowdd:studentmanager:1.0:*:*:*:*:*:*:*

History

05 Mar 2026, 21:31

Type Values Removed Values Added
Summary
  • (es) Se ha detectado una vulnerabilidad de seguridad en ZeroWdd studentmanager hasta 2151560fc0a50ec00426785ec1e01a3763b380d9. Esto afecta a la función addLeave del archivo src/main/java/com/wdd/studentmanager/controller/LeaveController.java. La manipulación del argumento Reason for Leave conduce a cross-site scripting. El ataque puede ser iniciado de forma remota. El exploit ha sido divulgado públicamente y puede ser utilizado. Este producto utiliza un modelo de lanzamiento continuo para entregar actualizaciones continuas. Como resultado, la información de versión específica para las versiones afectadas o actualizadas no está disponible. El repositorio de código del proyecto no ha estado activo durante muchos años.
First Time Zerowdd studentmanager
Zerowdd
References () https://vuldb.com/?ctiid.344904 - () https://vuldb.com/?ctiid.344904 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.344904 - () https://vuldb.com/?id.344904 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.750217 - () https://vuldb.com/?submit.750217 - Third Party Advisory, VDB Entry
References () https://www.yuque.com/clockw1se/lts9x9/mxgrzspnzmpxu7e7 - () https://www.yuque.com/clockw1se/lts9x9/mxgrzspnzmpxu7e7 - Exploit, Third Party Advisory
CPE cpe:2.3:a:zerowdd:studentmanager:1.0:*:*:*:*:*:*:*

09 Feb 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 02:16

Updated : 2026-03-05 21:31


NVD link : CVE-2026-2201

Mitre link : CVE-2026-2201

CVE.ORG link : CVE-2026-2201


JSON object : View

Products Affected

zerowdd

  • studentmanager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')