PT-2026-45271 · Unknown · Student Management System By Php
Fybox
·
Published
2026-06-01
·
Updated
2026-06-01
·
CVE-2026-10227
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
raisulislamg4 student management system by php versions up to 310d950e09013d5133c6b9210aff9444382d16d1
Description
An issue exists in the User Creation Handler component within the file 'add user check.php'. The manipulation of the
role argument allows for remote SQL injection, which is a technique where malicious SQL statements are inserted into entry fields for execution.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the file 'add user check.php' or avoid using the
role parameter in that file to minimize the risk of exploitation.Exploit
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Student Management System By Php