PT-2026-22604 · Code Projects · Simple Student Alumni System
Zhang Qi
·
Published
2026-03-02
·
Updated
2026-03-07
·
CVE-2026-26696
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
code-projects Simple Student Alumni System version 1.0
Description
The software contains a SQL Injection flaw in the
/TracerStudy/recordteacher edit.php file. The vulnerability exists due to insufficient sanitization of user-supplied input. The vulnerable parameter is not specified. The recordteacher edit.php file is susceptible to exploitation via crafted input.Recommendations
Apply input validation and parameterized queries to the
/TracerStudy/recordteacher edit.php file to prevent SQL Injection.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Student Alumni System