Back to VulnFeed / CVE-2026-7491
root@hackertop:~/vulnfeed/CVE-2026-7491#
CVE-2026-7491 HIGH CVE ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

Zyosoft School App up to 1.1.61/2.7.1 authorization

School App 19d ago Impact pending confirmation
LIFECYCLE
7.0 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability, which was classified as critical, has been found in Zyosoft School App up to 1.1.61/2.7.1. This issue affects an unknown part. Upgrading to version 1.1.62 or 2.7.2 eliminates this vulnerability.
Root Cause Analysis
Using CWE to declare the problem leads to CWE-639. The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Impact: Impacted is confidentiality, integrity, and availability.

Countermeasure: Upgrading to version 1.1.62 or 2.7.2 eliminates this vulnerability.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-7491 · CVSS 7.0 · Active Threat