SQL Injection Vulnerability in Student Management System by Raisulislamg4
CVE-2026-10227

6.9MEDIUM

Key Information:

Vendor
CVE Published:
1 June 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-10227?

A security vulnerability has been identified in Raisulislamg4's student management system affecting the user creation process via the add_user_check.php file. The vulnerability arises from improper handling of the 'role' argument, susceptible to SQL injection attacks. This allows attackers to manipulate database queries, potentially leading to unauthorized access and data compromise. Remote exploitation is possible, and details have been publicly disclosed. The project developers were notified of the issue, yet a response has not been received to date.

Affected Version(s)

student_management_system_by_php 310d950e09013d5133c6b9210aff9444382d16d1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fybox (VulDB User)
VulDB CNA Team
.