📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Technology/AI Services LOW 1h Global vulnerability Information Technology CRITICAL 4h Global vulnerability Information Technology CRITICAL 5h Global vulnerability Software and Technology HIGH 5h Global vulnerability Software and Cloud Services CRITICAL 5h Global phishing Artificial Intelligence and Email Security HIGH 6h Global phishing Email and Communications CRITICAL 7h Global vulnerability Enterprise Software / E-commerce CRITICAL 7h Global supply_chain Software Development and Technology CRITICAL 7h Global vulnerability Information Technology HIGH 8h Global general Technology/AI Services LOW 1h Global vulnerability Information Technology CRITICAL 4h Global vulnerability Information Technology CRITICAL 5h Global vulnerability Software and Technology HIGH 5h Global vulnerability Software and Cloud Services CRITICAL 5h Global phishing Artificial Intelligence and Email Security HIGH 6h Global phishing Email and Communications CRITICAL 7h Global vulnerability Enterprise Software / E-commerce CRITICAL 7h Global supply_chain Software Development and Technology CRITICAL 7h Global vulnerability Information Technology HIGH 8h Global general Technology/AI Services LOW 1h Global vulnerability Information Technology CRITICAL 4h Global vulnerability Information Technology CRITICAL 5h Global vulnerability Software and Technology HIGH 5h Global vulnerability Software and Cloud Services CRITICAL 5h Global phishing Artificial Intelligence and Email Security HIGH 6h Global phishing Email and Communications CRITICAL 7h Global vulnerability Enterprise Software / E-commerce CRITICAL 7h Global supply_chain Software Development and Technology CRITICAL 7h Global vulnerability Information Technology HIGH 8h
Vulnerabilities

CVE-2026-11533

Medium
CWE-266 — Weakness Type
Published: Jun 8, 2026  ·  Modified: Jun 10, 2026  ·  Source: NVD
CVSS v3
5.4
🔗 NVD Official
📄 Description (English)

A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this vulnerability is an unknown functionality of the file /see.php of the component Student Deletion Endpoint. The manipulation of the argument del leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

🤖 AI Executive Summary

CVE-2026-11533 is a medium-severity improper authorization vulnerability in an open-source student management system affecting the student deletion endpoint. The vulnerability allows remote attackers to manipulate the 'del' parameter to bypass authorization controls, potentially enabling unauthorized deletion of student records. With public exploit disclosure and no patch available, this poses immediate risk to educational institutions using this system.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Jun 8, 2026 22:08
🇸🇦 Saudi Arabia Impact Assessment
Saudi educational institutions (universities, colleges, and K-12 schools) using this student management system face direct risk of unauthorized student record manipulation. Government education sector (Ministry of Education) and private educational institutions are most vulnerable. Secondary impact on healthcare institutions using similar systems for student/patient record management. The vulnerability could lead to data integrity issues, unauthorized access to sensitive student information, and disruption of educational operations.
🏢 Affected Saudi Sectors
Education (Universities, Colleges, K-12 Schools) Government (Ministry of Education) Healthcare (if using similar systems) Private Educational Institutions
⚖️ Saudi Risk Score (AI)
6.8
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Identify all instances of imvks786 student_management_system in your environment
2. Restrict network access to /see.php endpoint using WAF rules or firewall policies
3. Implement input validation on the 'del' parameter to reject suspicious values
4. Enable comprehensive logging and monitoring of student deletion operations

Compensating Controls:
5. Implement role-based access control (RBAC) verification before any deletion operation
6. Require multi-factor authentication for administrative functions
7. Deploy Web Application Firewall (WAF) rules to block requests with suspicious 'del' parameter patterns
8. Implement database-level constraints to prevent unauthorized deletions

Detection Rules:
9. Monitor for POST/GET requests to /see.php with 'del' parameter containing non-standard values
10. Alert on any student record deletions performed by non-administrative accounts
11. Track failed authorization attempts on the student deletion endpoint

Long-term:
12. Migrate to a patched version once available or switch to alternative student management systems with active security support
13. Conduct security code review of the student_management_system codebase
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع حالات نظام إدارة الطلاب imvks786 في بيئتك
2. تقييد الوصول إلى نقطة نهاية /see.php باستخدام قواعد WAF أو سياسات جدار الحماية
3. تنفيذ التحقق من صحة الإدخال على معامل 'del' لرفض القيم المريبة
4. تفعيل السجلات الشاملة ومراقبة عمليات حذف الطلاب

عناصر التحكم التعويضية:
5. تنفيذ التحقق من التحكم في الوصول القائم على الأدوار (RBAC) قبل أي عملية حذف
6. طلب المصادقة متعددة العوامل للوظائف الإدارية
7. نشر قواعد جدار تطبيقات الويب (WAF) لحظر الطلبات ذات أنماط معامل 'del' المريبة
8. تنفيذ قيود على مستوى قاعدة البيانات لمنع الحذف غير المصرح به

قواعد الكشف:
9. مراقبة طلبات POST/GET إلى /see.php بمعامل 'del' يحتوي على قيم غير قياسية
10. التنبيه على أي حذف لسجلات الطلاب من قبل حسابات غير إدارية
11. تتبع محاولات التفويض الفاشلة على نقطة نهاية حذف الطلاب

المدى الطويل:
12. الترقية إلى نسخة مصححة بمجرد توفرها أو التبديل إلى أنظمة إدارة طلاب بديلة بدعم أمان نشط
13. إجراء مراجعة أمان الكود لقاعدة كود نظام إدارة الطلاب
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.5.1.1 - Information Security Policies and Procedures A.6.1.1 - Access Control Policy A.6.2.1 - User Registration and De-registration A.6.2.2 - User Access Rights A.7.1.1 - Information Security Event Logging A.8.2.1 - Classification of Information Assets
🔵 SAMA CSF
ID.AC-1 - Access Control Policy and Procedures ID.AC-2 - Physical and Logical Access Controls DE.CM-1 - Detection and Analysis DE.CM-3 - Monitoring and Detection RS.MI-1 - Incident Response and Management
🟡 ISO 27001:2022
6.2 - User Access Management 8.2.1 - User Registration and Access Rights 8.2.2 - User Access Rights Review 8.2.3 - Change of User Access Rights 8.3.1 - Management of Privileged Access Rights 8.3.2 - Restriction of Access to Information 8.3.4 - Access Control to Program Source Code
📊 CVSS Score
5.4
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityL — Low / Local
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score5.4
CWECWE-266
EPSS0.04%
Exploit No
Patch ✗ No
Published 2026-06-08
Source Feed nvd
🇸🇦 Saudi Risk Score
6.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-266
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.