CVE-2025-11661 is a critical missing authentication vulnerability in ProjectsAndPrograms School Management System, specifically affecting oranbyte school_management_system up to version 6b6fae5426044f89c08d0dd101c7fa71f9042a59. With a CVSS score of 9.8, this flaw allows unauthenticated remote attackers to achieve full compromise (confidentiality, integrity, availability) with low attack complexity. Although the exploit has been made public, there is no evidence of active exploitation, nor are there Metasploit or Nuclei modules available. Community discussion and media coverage are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:oranbyte:school_management_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.