


Perceptive Security
SOC/SIEM Consultancy

School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows attackers to bypass authentication by inje…
Published:
25 March 2026 at 23:00:00
Alert date:
26 March 2026 at 13:04:30
Source:
nvd.nist.gov
Web Technologies, Database & Storage, Enterprise Applications
School Management System CMS version 1.0 contains a critical SQL injection vulnerability in its admin login functionality. The vulnerability exists in the username parameter of the processlogin endpoint, allowing attackers to bypass authentication mechanisms. Attackers can exploit this flaw using boolean-based blind SQL injection techniques to authenticate as administrator without valid credentials. This vulnerability enables complete administrative access to the system through malicious SQL payloads. The vulnerability has been assigned CVE-2018-25201 and is considered high severity due to the authentication bypass capability.
Technical details
Mitigation steps:
Affected products:
School Management System CMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25201
https://www.exploit-db.com/exploits/44727
https://www.vulncheck.com/advisories/school-management-system-cms-admin-login-sql-injection
https://www.wecodex.com/item/view/school-management-system-in-php-and-mysql/5
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
