Junglewise Threat Intelligence

CVE-2026-10111: sambitraj STUDENT-MANAGEMENT-SYSTEM SQL injection in login pages

CVE-2026-10111 · Severity: high · CVSS 7.3 · Published 2026-05-30

Technologies: Sambitraj Student Management System. Vendors: Sambitraj.

Executive brief

A security vulnerability exists in the Student Management System (SMS), a tool used by schools to manage student data and grades. An attacker can exploit the login page to gain unauthorized access to the database. This could lead to the theft of sensitive student and teacher information or disruption of school operations.

Technical details

A time-based blind SQL injection vulnerability exists in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0 within the admin_login.php, student_login.php, and teacher_login.php components. The application fails to sanitize or parameterize the 'email' POST parameter before embedding it directly into SQL queries (e.g., select * from admin where email = '$_POST[email]'). A remote, unauthenticated attacker can provide crafted payloads containing SQL commands like SLEEP() to infer sensitive data from the database based on response time delays. Although the project was notified via a GitHub issue, no patch is currently available.

Affected products

  • sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0

Timeline

  • 2026-05-03: disclosed: Issue reported on GitHub repository
  • 2026-05-30: advisory: CVE published by VulDB/NVD

References

Related threats