Executive brief
A security vulnerability exists in the Student Management System, a software tool used to manage student records and administrative data. An attacker can exploit this flaw to bypass security checks and insert unauthorized information into the database, such as fake student records or malicious scripts. This could lead to data corruption, unauthorized access to sensitive information, or the disruption of school administrative operations.
Technical details
A SQL injection vulnerability exists in the 'student_trans.php' file of the StudentManagementSystem (commit cb2f558). The root cause is a failure to implement authentication checks (missing confirm_logged_in call) combined with the direct concatenation of user-supplied POST parameters—specifically FIRST_NAME, Last_Name, and EMAIL—into an INSERT SQL statement. A remote, unauthenticated attacker can exploit this by sending a crafted POST request to the affected endpoint. This allows for unauthorized data insertion, potential extraction of database information, or the injection of Cross-Site Scripting (XSS) payloads into the student database. As of the advisory date, the project has not responded to the issue report.
Affected products
- yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203
Timeline
- 2026-04-27: disclosed: Issue reported on GitHub repository
- 2026-05-25: advisory: CVE-2026-9470 published