Junglewise Threat Intelligence

CVE-2026-14750: mjperpinosa stumasy SQL injection in dictionary authorization

CVE-2026-14750 · Severity: high · CVSS 7.3 · Published 2026-07-05

Technologies: Mjperpinosa Stumasy. Vendors: Mjperpinosa.

Executive brief

A security vulnerability exists in stumasy, a student management and social networking platform. The software fails to properly verify passwords when users attempt to access the dictionary feature, allowing an attacker to bypass security checks. This could lead to unauthorized access to restricted information or the ability to manipulate data within the system's database.

Technical details

A SQL injection vulnerability exists in the `Notes_controller::accessing_dictionary_authorization` function within `application/PHP/objects/notes/accessing_dictionary_authorization.php`. The application concatenates the user-supplied 'Password' POST parameter directly into a SQL query string before calling `prepare()`, failing to utilize parameterized queries correctly. A remote, unauthenticated attacker can exploit this by providing a crafted password payload (e.g., using boolean logic like `') OR 1=1 -- -`) to bypass the dictionary authorization check. This flaw allows for authentication bypass and potentially broader database information extraction or manipulation. As of the advisory date, no official patch has been released by the maintainer.

Affected products

  • mjperpinosa stumasy up to 327d1b0f2915ba79d7ef8ebb74553e987609d9be

Timeline

  • 2026-06-05: disclosed: Issue reported to the project maintainer via GitHub issue #6
  • 2026-07-05: advisory: CVE-2026-14750 published by VulDB/NVD

References

Related threats