Executive brief
A security vulnerability exists in the StudentManagementSystem, a software tool used to manage large student records. An attacker can exploit this flaw to bypass security controls and potentially access or modify sensitive student data. This could lead to unauthorized data exposure and disruption of administrative operations.
Technical details
A SQL injection vulnerability exists in the StudentManagementSystem (commit cb2f558) within the success.php file. The flaw is caused by improper neutralization of the 'User' argument, allowing an attacker to inject malicious SQL commands. This vulnerability can be exploited remotely without authentication to bypass login mechanisms or access sensitive database information. A public exploit has been disclosed, and the project currently uses a rolling release model with no official patch yet confirmed by the maintainer.
Affected products
- yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203
Timeline
- 2026-05-25: advisory: NVD publication date
- 2026-05-25: disclosed: Public exploit made available