ZeroWdd Student Manager Improper Authorization Vulnerability in Teacher Controller

Vulnerability

A critical vulnerability has been identified in ZeroWdd's Student Manager version 1.0. This issue resides in the TeacherController.java file, specifically within the '/getTeacherList' endpoint. The vulnerability arises from improper authorization, allowing students to access data they should not be able to. This flaw can be exploited remotely.

Impact

Exploitation of this vulnerability allows for unauthorized access to teacher data, potentially leading to privilege escalation by allowing students to act as administrators.

Reproduction

To reproduce this vulnerability, send a POST request to the '/teacher/getTeacherList' endpoint. Include a JSESSIONID cookie to simulate an active session. The request can be made using a web browser or a tool like Postman, ensuring to set the 'X-Requested-With' header to 'XMLHttpRequest'.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.0
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.