Junglewise Threat Intelligence

CVE-2026-9474: yashpokharna2555 StudentManagementSystem SQL injection in studentdel.php

CVE-2026-9474 · Severity: high · CVSS 7.3 · Published 2026-05-25

Technologies: Yashpokharna2555 StudentManagementSystem. Vendors: Yashpokharna2555.

Executive brief

A security vulnerability exists in the StudentManagementSystem, a platform used for managing large student records. An attacker can exploit this flaw to remotely manipulate database commands, potentially leading to the unauthorized deletion or modification of student data. This could result in significant data loss and disruption of administrative operations.

Technical details

A SQL injection vulnerability exists in the yashpokharna2555 StudentManagementSystem up to commit cb2f558. The flaw is located in the confirm_logged_in function within the /studentdel.php file. By manipulating the 'ID' argument, a remote attacker can inject malicious SQL commands without requiring prior authentication. This can lead to unauthorized data retrieval, modification, or deletion from the underlying MySQL database. As of the advisory date, the project has not responded to the issue report, and no official patch is available.

Affected products

  • yashpokharna2555 StudentManagementSystem up to cb2f558ddf8d19396de0f92abf2d224d46a0a203

Timeline

  • 2026-05-25: advisory: Vulnerability published by VulDB/NVD
  • 2026-05-25: disclosed: Public exploit made available

References