CVE-2026-11336
6.3 MEDIUMA vulnerability has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dc...
Published: 2026-06-05 · Last updated: 2026-06-09
Severity and scoring
- CVSS
- 6.3 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- CWE
- CWE-266, CWE-285
Description
A vulnerability has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. Affected is an unknown function of the file dashboard_page/admin_page.php of the component Admin Interface. The manipulation of the argument UserAuthData leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-11336
- [Other]https://github.com/tittuvarghese/CollegeManagementSystem/
- [Other]https://github.com/tittuvarghese/CollegeManagementSystem/issues/5
- [Other]https://vuldb.com/cve/CVE-2026-11336
- [Other]https://vuldb.com/submit/832582
- [Other]https://vuldb.com/vuln/368874
- [Other]https://vuldb.com/vuln/368874/cti
- [Other]https://vuldb.com/submit/832582
Related CVEs
Same CWE
- CVE-2026-49060 — Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation (9.8 CRITICAL)
- CVE-2026-53814 — OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped ... (8.3 HIGH)
- CVE-2026-47169 — Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support
- CVE-2026-47342 — A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue...
- CVE-2026-46668 — SpiceDB is an open source database system for creating and managing security-critical application permissions