


Perceptive Security
SOC/SIEM Consultancy

A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This vulnerability affects unknown code of…
Published:
5 april 2026 om 22:00:00
Alert date:
6 april 2026 om 18:04:04
Source:
nvd.nist.gov
Web Technologies
A SQL injection vulnerability has been discovered in the Cyber-III Student-Management-System affecting the /login.php file's Parameter Handler component. The vulnerability allows remote attackers to manipulate the Password argument to perform SQL injection attacks. The exploit has been publicly disclosed and can be actively used. The affected system uses rolling releases, making version tracking difficult. The project maintainers have been notified through an issue report but have not yet responded to address the vulnerability.
Technical details
Mitigation steps:
Affected products:
Cyber-III Student-Management-System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-5669
https://github.com/Cyber-III/Student-Management-System/
https://github.com/Cyber-III/Student-Management-System/issues/240
https://vuldb.com/submit/785942
https://vuldb.com/vuln/355491
https://vuldb.com/vuln/355491/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
