top of page
perceptive_background_267k.jpg

A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. Affe…

Published:

4 augustus 2026 om 22:00:00

Alert date:

5 augustus 2026 om 21:03:13

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage, Identity & Access

A SQL injection vulnerability has been identified in the imranrisal-dev Student-Management-System, specifically in the loginCheckTest.php file within the Login component. The vulnerability allows manipulation of the username and password arguments to perform SQL injection attacks. The attack can be launched remotely without authentication, and a public exploit is already available. The product does not use versioning, making it impossible to identify affected versus unaffected releases. The vendor was notified prior to disclosure but did not respond. This represents a significant risk as it targets the authentication mechanism of an educational management system.

Technical details

Mitigation steps:

Affected products:

imranrisal-dev Student-Management-System

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page