StudentManager Improper Authorization Vulnerability in Teacher String Handler Component
Vulnerability
A vertical privilege escalation vulnerability has been identified in the StudentManager project by huanfenz, affecting versions through 1.0. The issue arises in the Teacher String Handler component, where improper authorization allows users to access data and interfaces beyond their assigned privileges. This vulnerability can be exploited remotely.
Impact
Exploitation of this vulnerability allows for unauthorized access to administrative interfaces and data, bypassing normal permission controls.
Reproduction
The vulnerability can be reproduced by manipulating the request path to include directory traversal sequences that bypass authorization checks. For example, adding 'clazz/../teacher/../../' to the request path can exploit the vulnerability by accessing restricted interfaces and data.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
