OVERVIEW CVE-2026-5671 is a cross-site scripting (XSS) vulnerability in the Cyber-III Student-Management-System, specifically affecting the Class Schedule Deletion Endpoint located at /admin/class%20schedule/delete_batch.php. The vulnerability stems from improper input validation of the "batch" parameter, allowing attackers to inject malicious scripts. The affected product does not use versioning; however, the vulnerability has been confirmed through commit hash 1a938fa61e9f735078e9b291d2e6215b4942af3f. SEVERITY The vulnerability carries a CVSS v3.1 score of 4.3 (MEDIUM severity) with a network attack vector requiring no privileges but user interaction. Attack complexity is low, meaning exploitation is straightforward once user engagement is achieved. The impact is limited to integrity compromise with no confidentiality or availability impact, reflecting the nature of reflected XSS attacks. The FAUCET Risk Score of 30.0/100 indicates moderate concern within the broader threat landscape. EXPLOITATION STATUS Exploit code has been publicly disclosed, increasing the practical risk of exploitation. However, the vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no active exploitation indicators. The extremely low EPSS score of 0.00035 suggests minimal real-world exploitation likelihood. The development team was notified through an issue report but has not responded, indicating a lack of active remediation efforts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cyber-III | Student-Management-System | 1a938fa61e9f735078e9b291d2e6215b4942af3fCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.