Description
A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This affects an unknown function of the file /index.ph of the component Login. Such manipulation of the argument usr/pwd leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-06-08
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

unsanitized user credentials supplied to the login endpoint in /index.ph allow an attacker to inject arbitrary SQL code; the exploit can be launched remotely by anyone with network access to the web application, and the source code is publicly available, making replication straightforward. Successful exploitation could read, modify, or delete database records, resulting in confidentiality and integrity loss for the management system.

Affected Systems

the vulnerability affects the imvks786 Student Management System, as noted by the CNA vendor name, with all releases up to commit 9599b560ad3c3b83e75d328b76bedcd489ef1f46 potentially vulnerable. The project follows a rolling release model, so a specific fixed version is not yet identified; any deployment built before the fix remains at risk.

Risk and Exploitability

the CVSS score of 6.9 classifies the weakness as medium severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog; however, because exploitation is possible remotely and a public exploit already exists, the likelihood of real-world attacks remains significant. Attackers can achieve the SQL injection from any external host capable of reaching the application URL.

Generated by OpenCVE AI on June 8, 2026 at 18:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to a fixed release once the developer releases a fix
  • If an update is not available, modify the login code to validate and sanitize the usr and pwd inputs, and employ parameterized queries to eliminate injection vectors
  • Restrict external access to the login page with firewall rules or IP whitelisting, and monitor authentication logs for repeated injection attempts

Generated by OpenCVE AI on June 8, 2026 at 18:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 08 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 08 Jun 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This affects an unknown function of the file /index.ph of the component Login. Such manipulation of the argument usr/pwd leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.
Title imvks786 student_management_system Login index.ph sql injection
First Time appeared Imvks786
Imvks786 student Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:imvks786:student_management_system:*:*:*:*:*:*:*:*
Vendors & Products Imvks786
Imvks786 student Management System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Imvks786 Student Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-08T17:35:35.286Z

Reserved: 2026-06-07T19:53:18.688Z

Link: CVE-2026-11530

cve-icon Vulnrichment

Updated: 2026-06-08T17:35:30.945Z

cve-icon NVD

Status : Received

Published: 2026-06-08T17:16:40.017

Modified: 2026-06-08T17:16:40.017

Link: CVE-2026-11530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-08T18:30:16Z

Weaknesses