Title: SourceCodester Student Result Management System 1.0 1.0 Improper Access Controls Description: A critical vulnerability was found in SourceCodester Student Result Management System 1.0, located in the /admin/core/import_users.php file. The application does not perform authentication or session validation checks before processing file uploads, allowing an unauthenticated remote attacker to upload a specially crafted Excel (.xlsx) file. This leads to the creation of unauthorized "Teacher" accounts with persistent database pollution. Source: GitHub Link User: yan1451 (UID 94854) Submission Date: 02/11/2026 Moderation Date: 02/22/2026 Status: Accepted VulDB Entry: 2347366 Points: 20