Imranrisal Dev · Student Management System · CVE-2026-18958
**Name of the Vulnerable Software and Affected Versions**
imranrisal-dev Student-Management-System (affected versions not specified)
**Description**
A remote SQL injection is possible within the Login component via the `loginCheckTest.php` file. This occurs when the `username` and `password` arguments are manipulated, allowing an attacker to interfere with the database queries.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.