Imvks786 · Student Management System · CVE-2026-11531
**Name of the Vulnerable Software and Affected Versions**
imvks786 student management system versions prior to 9599b560ad3c3b83e75d328b76bedcd489ef1f46
**Description**
A remote SQL injection is possible within the Administrator Login Endpoint. The issue occurs in the `admin/admin login.php` file when manipulating the `a usr` and `a pwd` arguments. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.
**Recommendations**
Update imvks786 student management system to a version later than 9599b560ad3c3b83e75d328b76bedcd489ef1f46.
As a temporary workaround, restrict access to the `admin/admin login.php` file to minimize the risk of exploitation.