SQL Injection Vulnerability in Imranrisal-Dev Student Management System Login Component
CVE-2026-18958

6.9MEDIUM

Key Information:

Vendor
CVE Published:
5 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-18958?

The Imranrisal-Dev Student-Management-System is susceptible to SQL injection through the loginCheckTest.php file. By manipulating the username and password parameters, an attacker can execute unauthorized SQL commands, potentially compromising the database and gaining access to sensitive information. This vulnerability can be exploited remotely, posing significant security risks. The vendor has not responded to disclosures concerning this issue, leaving the product unpatched and vulnerable to attacks.

Affected Version(s)

Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def

Student-Management-System a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

HackNine (VulDB User)
VulDB CNA Team
.