6.3 CVE-2026-10271

Enriched by CISA
 

A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The affected element is an unknown function of the file admin/ of the component Admin Endpoint. This manipulation of the argument uid causes execution after redirect. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. Multiple endpoints are affected. The project was informed of the problem early through an issue report but has not responded yet.
https://nvd.nist.gov/vuln/detail/CVE-2026-10271

Categories

CWE-698 : Execution After Redirect (EAR)
The web application sends a redirect to another location, but instead of exiting, it executes additional code. This issue might not be detected if testing is performed using a web browser, because the browser might obey the redirect and move the user to a different page before the application has produced outputs that indicate something is amiss. Execution-after-redirect allows access to application configuration details. chain: library file sends a redirect if it is directly requested but continues to execute, allowing remote file inclusion and path traversal. Remote attackers can obtain access to administrator functionality through EAR. Remote attackers can obtain access to administrator functionality through EAR. Bypass of authentication step through EAR. Chain: Execution after redirect triggers eval injection. chain: execution after redirect allows non-administrator to perform static code injection.

References


 

AFFECTED (from MITRE)


Vendor Product Versions
a4m4 Student-Management-System
  • f0c5f6842c5e8c431ff02b5260a565ca844df3a0 [affected]
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

CPE

cpe start end


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry