PT-2026-47335 · Imvks786 · Student Management System

·

CVE-2026-11531

·

Published

2026-06-08

·

Updated

2026-06-08

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions imvks786 student management system versions prior to 9599b560ad3c3b83e75d328b76bedcd489ef1f46
Description A remote SQL injection is possible within the Administrator Login Endpoint. The issue occurs in the admin/admin login.php file when manipulating the a usr and a pwd arguments. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.
Recommendations Update imvks786 student management system to a version later than 9599b560ad3c3b83e75d328b76bedcd489ef1f46. As a temporary workaround, restrict access to the admin/admin login.php file to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11531

Affected Products

Student Management System