Unknown · Soarkey Studentmanagement · CVE-2026-82620
**Name of the Vulnerable Software and Affected Versions**
Soarkey StudentManagement versions up to e08f7f1d5015af407aa4cca0ada3dea189b4937e
学生信息管理系统 versions up to e08f7f1d5015af407aa4cca0ada3dea189b4937e
**Description**
A security flaw allows remote attackers to perform SQL injection, a technique used to manipulate database queries. The issue exists in the `CourseDao.course ranking()` function within the `code/src/dao/CourseDao.java` file when the `cno` argument is manipulated.
**Recommendations**
As a temporary workaround, restrict access to the `CourseDao.course ranking()` function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.