Junglewise Threat Intelligence

CVE-2026-10227: raisulislamg4 Student Management System SQL injection in add_user_check.php

CVE-2026-10227 · Severity: high · CVSS 7.3 · Published 2026-06-01

Technologies: Raisulislamg4 Student Management System by PHP. Vendors: Raisulislamg4.

Executive brief

A security vulnerability in the Student Management System by PHP allows unauthorized individuals to create new user accounts with administrative privileges. This software is used to manage student records and administrative tasks. By exploiting this flaw, an attacker can gain full control over the system, accessing sensitive student data and disrupting school operations without needing any existing login credentials.

Technical details

The vulnerability exists in the `add_user_check.php` file of the Student Management System by PHP. The script fails to implement any authentication or authorization checks before processing user creation requests. Furthermore, it directly concatenates the `role` parameter from POST requests into an SQL INSERT statement, leading to SQL injection. An unauthenticated remote attacker can send a crafted POST request to create a new account with the 'admin' role. This allows for complete privilege escalation and full system compromise. As of the advisory date, no official patch has been released by the maintainer.

Affected products

  • raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1

Timeline

  • 2026-05-08: disclosed: Issue reported to the developer on GitHub.
  • 2026-06-01: advisory: CVE published and added to NVD.

References

Related threats