SQL Injection Vulnerability in Imranrisal-Dev Student Management System Login Component
CVE-2026-18958
Key Information:
- Vendor
Imranrisal-dev
- Vendor
- CVE Published:
- 5 August 2026
Badges
What is CVE-2026-18958?
The Imranrisal-Dev Student-Management-System is susceptible to SQL injection through the loginCheckTest.php file. By manipulating the username and password parameters, an attacker can execute unauthorized SQL commands, potentially compromising the database and gaining access to sensitive information. This vulnerability can be exploited remotely, posing significant security risks. The vendor has not responded to disclosures concerning this issue, leaving the product unpatched and vulnerable to attacks.
Affected Version(s)
Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def
Student-Management-System a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
