Unrestricted File Upload Vulnerability in Student Management System by Imranrisal
CVE-2026-18927

5.3MEDIUM

Key Information:

Vendor
CVE Published:
5 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-18927?

The imranrisal-dev Student Management System contains a vulnerability in the function storeProfileImage located in student_profile_pic.php. This flaw allows for unrestricted file uploads when manipulating the argument choose_file, potentially leading to remote code execution. As the exploit is publicly available, it poses a significant risk for users of the system. The rolling release model of the product complicates identification of specific affected versions, and efforts to notify the vendor went unanswered.

Affected Version(s)

Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def

Student-Management-System a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

HackEight (VulDB User)
VulDB CNA Team
.