PT-2026-22604 · Code Projects · Simple Student Alumni System
Zhang Qi
·
Publicado
2026-03-02
·
Atualizado
2026-03-07
·
CVE-2026-26696
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
code-projects Simple Student Alumni System version 1.0
Description
The software contains a SQL Injection flaw in the
/TracerStudy/recordteacher edit.php file. The vulnerability exists due to insufficient sanitization of user-supplied input. The vulnerable parameter is not specified. The recordteacher edit.php file is susceptible to exploitation via crafted input.Recommendations
Apply input validation and parameterized queries to the
/TracerStudy/recordteacher edit.php file to prevent SQL Injection.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Simple Student Alumni System