Description
A vulnerability has been found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. Impacted is the function mysql_error of the file login.php of the component Login Endpoint. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-06
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote SQL Injection leading to unauthorized access
Action: Assess Impact
AI Analysis

Impact

The vulnerability exists in the login.php file of the Kusalkasilva Learning‑Management‑System. The mysql_error function processes the username and password parameters without proper sanitization, allowing attackers to inject arbitrary SQL. This flaw is listed as CWE‑74 and CWE‑89 and can be exploited remotely to read, alter, or delete data held by the system. The CVSS score of 6.9 indicates a medium severity when the application is exposed, and attackers could potentially gain unauthorized access to user accounts or obtain sensitive data.

Affected Systems

Affected systems comprise all deployments of the Kusalkasilva Learning‑Management‑System that include the vulnerable commit ffeb873f8803f1e9664384ff75000c7da45466d2. Continuous delivery with rolling releases means that the exact targeted release is not specified, and no patched or fixed versions have been released yet. Every installation using the public code base before the update is considered vulnerable.

Risk and Exploitability

The vulnerability is exploitable over the network, and the public disclosure indicates that exploits are available, although the EPSS value is not disclosed and the issue is not in the KEV catalog. The lack of a vendor patch combined with the remote attack vector raises the risk level for applications exposed to the internet. Organizations should treat this as a medium‑to‑high risk until a proper fix or mitigations are applied.

Generated by OpenCVE AI on October 6, 2026 at 13:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disallow direct access to login.php from non‑trusted networks by configuring the web server or firewall to permit only internal IP ranges
  • Update the application to a version that removes the use of mysql_error for authentication, or apply a code patch that sanitizes the username and password inputs and utilizes prepared statements
  • Add input validation or escaping for all data incorporated into SQL queries, following best practices for PHP such as using PDO or MySQLi with bound parameters

Generated by OpenCVE AI on October 6, 2026 at 13:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 12:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. Impacted is the function mysql_error of the file login.php of the component Login Endpoint. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Title Kusalkasilva Learning-Management-System Login Endpoint login.php mysql_error sql injection
First Time appeared Kusalkasilva
Kusalkasilva learning-management-system
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:kusalkasilva:learning-management-system:*:*:*:*:*:*:*:*
Vendors & Products Kusalkasilva
Kusalkasilva learning-management-system
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Kusalkasilva Learning-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-06T11:45:14.525Z

Reserved: 2026-10-06T05:49:17.217Z

Link: CVE-2026-105918

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T12:16:47.287

Modified: 2026-10-06T12:16:47.287

Link: CVE-2026-105918

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T13:45:18Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')