Back

CVE-2019-11196

CRITICAL

An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote attackers to gain administrator privileges via the Teachers Web Panel (TWP) User ID or Password field. If exploited, the attackers could perform any actions with administrator privileges (e.g., enumerate/delete all the students' personal information or modify various settings).

Published: Apr 12, 2019 Modified: Jun 17, 2026
CWE-89

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
vpcsbd integrated_university_management_system *

GitHub Security Advisory GHSA-xv8x-7495-j62f

An authentication bypass vulnerability in all versions of ValuePLUS Integrated University...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 6.27%

Top 7% most likely to be exploited

Threat Score 41.1 / 100

Data Sources

NVD EPSS GitHub