Unrestricted File Upload Vulnerability in Student Management System by Imranrisal
CVE-2026-18927
Key Information:
- Vendor
Imranrisal-dev
- Vendor
- CVE Published:
- 5 August 2026
Badges
What is CVE-2026-18927?
The imranrisal-dev Student Management System contains a vulnerability in the function storeProfileImage located in student_profile_pic.php. This flaw allows for unrestricted file uploads when manipulating the argument choose_file, potentially leading to remote code execution. As the exploit is publicly available, it poses a significant risk for users of the system. The rolling release model of the product complicates identification of specific affected versions, and efforts to notify the vendor went unanswered.
Affected Version(s)
Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def
Student-Management-System a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
