SQL Injection Vulnerability in Student Management System by Raisulislamg4
CVE-2026-10227
Key Information:
- Vendor
Raisulislamg4
- Vendor
- CVE Published:
- 1 June 2026
Badges
What is CVE-2026-10227?
A security vulnerability has been identified in Raisulislamg4's student management system affecting the user creation process via the add_user_check.php file. The vulnerability arises from improper handling of the 'role' argument, susceptible to SQL injection attacks. This allows attackers to manipulate database queries, potentially leading to unauthorized access and data compromise. Remote exploitation is possible, and details have been publicly disclosed. The project developers were notified of the issue, yet a response has not been received to date.
Affected Version(s)
student_management_system_by_php 310d950e09013d5133c6b9210aff9444382d16d1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
