Junglewise Threat Intelligence

CVE-2026-37750: mahmoudai1 School Management System reflected XSS in register.php

CVE-2026-37750 · Severity: medium · CVSS 6.1 · Published 2026-04-28

Technologies: Mahmoudai1 School Management System.

Executive brief

A security vulnerability exists in the School Management System, a web application used to manage student and teacher records. An attacker can trick a user into clicking a specially crafted link, allowing the attacker to run malicious code in the user's web browser. This could lead to the theft of login credentials, unauthorized access to school data, or the redirection of users to fraudulent websites.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in the register.php file of the School Management System 1.0. The application fails to sanitize the 'type' GET/REQUEST parameter before reflecting it into the HTML output at line 22 (within an <h1> tag) and line 26 (within a <form action> attribute). An unauthenticated remote attacker can exploit this by inducing a user to visit a crafted URL containing a malicious JavaScript payload. Successful exploitation allows for session hijacking via cookie theft, phishing, or unauthorized redirection. The vulnerability can be remediated by applying htmlspecialchars() to the affected PHP echo statements.

Affected products

  • mahmoudai1 School Management System 1.0

Timeline

  • 2026-04-16: disclosed: Vulnerability discovered by Varad AP Mene
  • 2026-04-28: advisory: CVE-2026-37750 published by MITRE/NVD

References