Junglewise Threat Intelligence

CVE-2026-14749: mjperpinosa stumasy code injection in imba_calculator

CVE-2026-14749 · Severity: high · CVSS 7.3 · Published 2026-07-05

Technologies: Mjperpinosa Stumasy. Vendors: Mjperpinosa.

Executive brief

A vulnerability exists in stumasy, a student management and social networking platform. The software's calculator feature allows an attacker to run unauthorized commands on the server. This could lead to the theft of student data, modification of website content, or a complete takeover of the hosting server.

Technical details

A code injection vulnerability exists in mjperpinosa stumasy up to commit 327d1b0f2915ba79d7ef8ebb74553e987609d9be. The issue is located in 'application/pages/imba_calculator/calculate.php', where the 'mathematical_sentence' POST parameter is decoded from JSON and its 'value' field is passed directly to the PHP eval() function without sanitization. A remote, unauthenticated attacker can exploit this by sending a specially crafted JSON payload to execute arbitrary PHP code in the context of the web server. This can lead to full system compromise, including local file disclosure and remote command execution. As of the advisory date, no patch has been released by the vendor.

Affected products

  • mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be

Timeline

  • 2026-06-05: disclosed: Issue reported to developer via GitHub issue tracker
  • 2026-07-05: advisory: CVE published by VulDB/NVD

References

Related threats