


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. Affe…
Published:
5 augustus 2026 om 00:00:00
Alert date:
5 augustus 2026 om 23:03:13
Source:
nvd.nist.gov
Web Technologies, Database & Storage, Identity & Access
A SQL injection vulnerability has been identified in the imranrisal-dev Student-Management-System, specifically in the loginCheckTest.php file within the Login component. The vulnerability allows manipulation of the username and password arguments to perform SQL injection attacks. The attack can be launched remotely without authentication, and a public exploit is already available. The product does not use versioning, making it impossible to identify affected versus unaffected releases. The vendor was notified prior to disclosure but did not respond. This represents a significant risk as it targets the authentication mechanism of an educational management system.
Technical details
Mitigation steps:
Affected products:
imranrisal-dev Student-Management-System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18958
https://github.com/winterbergnurullah551-sketch/sql-cves/issues/1
https://vuldb.com/cve/CVE-2026-18958
https://vuldb.com/submit/860107
https://vuldb.com/vuln/386233
https://vuldb.com/vuln/386233/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
