Junglewise Threat Intelligence

CVE-2026-11531: imvks786 student_management_system SQL injection in admin_login.php

CVE-2026-11531 · Severity: high · CVSS 7.3 · Published 2026-06-08

Technologies: Imvks786 Student Management System.

Executive brief

A security vulnerability exists in the imvks786 Student Management System, a web application used for managing student records. An attacker can bypass the administrator login screen without a valid password by exploiting a flaw in how the system handles login credentials. This could allow an unauthorized person to gain full administrative control over the system, potentially leading to the theft or modification of sensitive student data.

Technical details

A SQL injection vulnerability exists in the Administrator Login Endpoint of the imvks786 student_management_system. The flaw is located in the 'admin/admin_login.php' file, where the 'a_usr' and 'a_pwd' POST parameters are directly embedded into a SQL query without sanitization or parameterization. A remote, unauthenticated attacker can exploit this by providing a crafted SQL payload (e.g., admin' OR '1'='1) in the username field to bypass the password check. Successful exploitation results in an active administrator session and full access to the admin dashboard. As of the advisory date, no official patch has been released by the maintainer.

Affected products

  • imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46

Timeline

  • 2026-05-25: disclosed: Issue reported to the project maintainer via GitHub
  • 2026-06-08: advisory: CVE published by VulDB/NVD

References