SQL Injection Vulnerability in sambitraj Student-Management-System Dashboard
CVE-2026-78056
Key Information:
- Vendor
Sambitraj
- Vendor
- CVE Published:
- 23 August 2026
Badges
What is CVE-2026-78056?
A SQL injection vulnerability exists in the Dashboard component of the sambitraj Student-Management-System. The flaw arises from improper handling of user input via the roll_no or teacher_name arguments, allowing an attacker to execute malicious SQL commands remotely. As this exploit is now publicly available, it poses a serious threat to systems using affected versions. Despite its disclosure, the vendor has yet to issue a response regarding a patch for this vulnerability.
Affected Version(s)
Student-Management-System 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
