Imranrisal Dev · Student Management System · CVE-2026-18927
**Name of the Vulnerable Software and Affected Versions**
imranrisal-dev Student-Management-System (affected versions not specified)
**Description**
A remote unrestricted upload issue exists within the Shared Upload Helper component. The problem occurs in the `storeProfileImage()` function located in the `student profile pic.php` file. By manipulating the `choose file` argument, an attacker can upload files without proper restrictions.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the `storeProfileImage()` function in the `student profile pic.php` file to minimize the risk of exploitation.