SQL Injection Vulnerability in Lavkush Maurya Student Registration System
CVE-2026-18896
Key Information:
- Vendor
Lavkush-maurya
- Vendor
- CVE Published:
- 5 August 2026
Badges
What is CVE-2026-18896?
The Lavkush Maurya Student Registration System 1.0 contains a vulnerability that allows for SQL injection through improper handling of the 'oldpass' argument in the /student/changepass.php file. This weakness can be exploited remotely, leading to unauthorized access and manipulation of the database. Publicly disclosed exploits have been reported, highlighting the urgent need for remediation. Despite attempts to notify the vendor, they have not responded to address this significant security concern.
Affected Version(s)
Student-Registration-System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
