Imvks786 · Student Management System · CVE-2026-11530
**Name of the Vulnerable Software and Affected Versions**
imvks786 student management system versions prior to 9599b560ad3c3b83e75d328b76bedcd489ef1f46
**Description**
A remote SQL injection occurs in the Login component within the `/index.ph` file. The issue arises from the improper handling of the `usr` and `pwd` arguments, allowing an attacker to execute arbitrary SQL commands.
**Recommendations**
Update imvks786 student management system to a version later than 9599b560ad3c3b83e75d328b76bedcd489ef1f46.
As a temporary mitigation, restrict access to the `/index.ph` file or the Login component.