A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. (CVE-2026-97650)
A cross-site scripting (XSS) vulnerability exists in the ningzichun student-management-system in the admin/fun/addLog.php file. The vulnerability arises from improper handling of the 'reason/detail' argument in the echo function, allowing remote attackers to inject malicious scripts. The issue has been publicly disclosed, but no official response or patch has been provided by the project.
AI Analysis
Technical Summary
CVE-2026-97650 describes a cross-site scripting vulnerability in the ningzichun student-management-system up to commit 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. The vulnerability is located in the echo function of admin/fun/addLog.php, where manipulation of the 'reason/detail' parameter leads to XSS. The attack can be performed remotely and requires no privileges, but user interaction is needed (UI:R). The vulnerability has a CVSS v3.1 score of 4.3 (low severity). The project was notified early but has not issued a patch or response. Public exploit details are available.
Potential Impact
The vulnerability allows remote attackers to perform cross-site scripting attacks by injecting malicious scripts via the 'reason/detail' parameter. This can lead to limited impact such as user interface manipulation or phishing within the affected application context. There is no direct confidentiality or availability impact reported.
Mitigation Recommendations
No official patch or fix is currently available as the project has not responded to the issue report. Users should apply caution when handling input to the affected function and consider implementing manual input sanitization or filtering as a temporary mitigation. Monitor the vendor or project repository for updates or official patches.
A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. (CVE-2026-97650)
Description
A cross-site scripting (XSS) vulnerability exists in the ningzichun student-management-system in the admin/fun/addLog.php file. The vulnerability arises from improper handling of the 'reason/detail' argument in the echo function, allowing remote attackers to inject malicious scripts. The issue has been publicly disclosed, but no official response or patch has been provided by the project.
CVSS v3.1
Score 4.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-97650 describes a cross-site scripting vulnerability in the ningzichun student-management-system up to commit 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. The vulnerability is located in the echo function of admin/fun/addLog.php, where manipulation of the 'reason/detail' parameter leads to XSS. The attack can be performed remotely and requires no privileges, but user interaction is needed (UI:R). The vulnerability has a CVSS v3.1 score of 4.3 (low severity). The project was notified early but has not issued a patch or response. Public exploit details are available.
Potential Impact
The vulnerability allows remote attackers to perform cross-site scripting attacks by injecting malicious scripts via the 'reason/detail' parameter. This can lead to limited impact such as user interface manipulation or phishing within the affected application context. There is no direct confidentiality or availability impact reported.
Mitigation Recommendations
No official patch or fix is currently available as the project has not responded to the issue report. Users should apply caution when handling input to the affected function and consider implementing manual input sanitization or filtering as a temporary mitigation. Monitor the vendor or project repository for updates or official patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-ppj4-rp9m-qmrp
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-97650"]
- Database Specific Severity
- LOW
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab5fb92f7a7c5410655d17b
Added to database: 09/25/2026, 04:41:54 UTC
Last enriched: 09/25/2026, 04:42:40 UTC
Last updated: 09/25/2026, 04:42:40 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.