CVE-2026-10169 | OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6 Forgot Password Endpoint Login.php ajax_forgot_password email password recovery

SecurityVulns

A vulnerability was found in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. It has been declared as problematic. Affected by this vulnerability is the function ajax_forgot_password of the file application/controllers/Login.php of the component Forgot Password Endpoint. The manipulation of the argument email results in weak password recovery.

This vulnerability is reported as CVE-2026-10169. The attack can be launched remotely. Moreover, an exploit is present.

This product does not use versioning. This is why information about affected and unaffected releases are unavailable.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More