Junglewise Threat Intelligence

CVE-2026-86267: itsourcecode Society Management System SQL injection in check_student.php

CVE-2026-86267 · Severity: medium · CVSS 6.3 · Published 2026-09-07

Vendors: Itsourcecode.

Executive brief

The Society Management System is a PHP-based student record application distributed by itsourcecode. An attacker can inject malicious SQL commands through the student_id parameter in the check_student.php file, allowing unauthorized access to or modification of the underlying database. This vulnerability does not require authentication and can be exploited remotely to exfiltrate sensitive student data or compromise system integrity.

Technical details

The vulnerability is a classic SQL injection flaw in the /society/check_student.php endpoint. The vulnerable code directly concatenates user-supplied POST parameter student_id into SQL queries without sanitization, filtering, or prepared statements. Remote attackers can send crafted SQL payloads (e.g., via time-based blind SQL injection or UNION-based queries) to extract database contents, modify records, or execute administrative operations. No authentication is required; the endpoint is directly accessible. While patches are not documented in the advisory, developers should immediately implement parameterized queries or prepared statements with bound variables.

Affected products

  • itsourcecode Society Management System 1.0

Timeline

  • 2026-07-23: disclosed: Vulnerability disclosed on GitHub
  • 2026-09-07: advisory: CVE-2026-86267 published

References