Project Subscriptions
No data.
No advisories yet.
Solution
Update School App (Android) to version 1.1.62 or later Update School App (iOS) to version 2.7.2 or later
Workaround
No workaround given by the vendor.
Sat, 02 May 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify a specific parameter to read and modify other users' data. | |
| Title | Zyosoft|School App - Insecure Direct Object Reference | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-05-02T09:14:25.760Z
Reserved: 2026-04-30T09:01:07.205Z
Link: CVE-2026-7491
No data.
Status : Received
Published: 2026-05-02T10:16:19.107
Modified: 2026-05-02T10:16:19.107
Link: CVE-2026-7491
No data.
OpenCVE Enrichment
No data.