Executive brief
A vulnerability exists in the imvks786 Student Management System, a web application used for managing educational records. An attacker can bypass the login screen to gain unauthorized access to the system as a student or administrator. This could lead to the theft of sensitive student data, unauthorized modification of permissions, or the deletion of academic records.
Technical details
A SQL injection vulnerability exists in the Login component of the imvks786 student_management_system due to improper neutralization of special elements in the 'usr' and 'pwd' parameters. Specifically, in index.php, user-supplied input is concatenated directly into SQL queries without parameterization or escaping. A remote, unauthenticated attacker can exploit this by sending a specially crafted POST request (e.g., using 'OR 1=1') to bypass authentication. Successful exploitation allows for full session establishment, unauthorized data deletion via see.php, and privilege escalation. As of the advisory date, no patch has been released by the maintainer.
Affected products
- imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46
Timeline
- 2026-05-25: disclosed: Issue reported to the developer via GitHub
- 2026-06-08: advisory: NVD/VulDB advisory published