No advisories yet.
Solution
Update School App (Android) to version 1.1.62 or later Update School App (iOS) to version 2.7.2 or later
Workaround
No workaround given by the vendor.
Mon, 04 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zyosoft
Zyosoft school App |
|
| Vendors & Products |
Zyosoft
Zyosoft school App |
Mon, 04 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 02 May 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify a specific parameter to read and modify other users' data. | |
| Title | Zyosoft|School App - Insecure Direct Object Reference | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-05-04T14:56:44.399Z
Reserved: 2026-04-30T09:01:07.205Z
Link: CVE-2026-7491
Updated: 2026-05-04T14:56:39.742Z
Status : Received
Published: 2026-05-02T10:16:19.107
Modified: 2026-05-02T10:16:19.107
Link: CVE-2026-7491
No data.
OpenCVE Enrichment
Updated: 2026-05-04T16:06:58Z