SQL Injection Vulnerability in PHPGurukul Student Information System
CVE-2026-82424
Key Information:
- Vendor
PHPgurukul
- Vendor
- CVE Published:
- 29 August 2026
Badges
What is CVE-2026-82424?
A security flaw has been discovered in the PHPGurukul Student Information System version 1.0, specifically in the /student_edit1.php file. This vulnerability arises due to improper handling of the ID argument, allowing attackers to execute SQL injection attacks remotely. The exploit has been publicly disclosed and poses a significant risk of unauthorized database access, which can lead to the manipulation or disclosure of sensitive information.
Affected Version(s)
Student Information System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
