Sambitraj · Student Management System · CVE-2026-82553
**Name of the Vulnerable Software and Affected Versions**
sambitraj Student Management System versions prior to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5
**Description**
Improper authorization occurs in the Student Dashboard component when the `roll no` argument is manipulated. This issue is triggered within the `mysqli query()` function located in the `student dashboard.php` file and can be exploited remotely.
**Recommendations**
Update sambitraj Student Management System to a version later than 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5.
As a temporary mitigation, restrict access to the `student dashboard.php` file or avoid using the `roll no` parameter until a patch is applied.