


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. Impacted is an unknown function of the f…
Published:
31 mei 2026 om 22:00:00
Alert date:
1 juni 2026 om 07:01:40
Source:
nvd.nist.gov
Web Technologies, Database & Storage
A SQL injection vulnerability has been discovered in raisulislamg4 student_management_system_by_php affecting the delete.php file. The flaw allows remote attackers to manipulate parameters including user_id, course_id, teacher_id, student_id, and application_id to execute SQL injection attacks. The exploit has been publicly disclosed and can be actively used. The affected system operates on a rolling release basis with no specific version numbers. Despite early notification through an issue report, the project maintainers have not responded to address the vulnerability.
Technical details
Mitigation steps:
Affected products:
student_management_system_by_php
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10226
https://github.com/raisulislamg4/student_management_system_by_php/
https://github.com/raisulislamg4/student_management_system_by_php/issues/3
https://vuldb.com/cve/CVE-2026-10226
https://vuldb.com/submit/822786
https://vuldb.com/vuln/367505
https://vuldb.com/vuln/367505/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
