PT-2026-83501 · Unknown · Phpgurukul Student Information System

·

CVE-2026-82424

·

Published

2026-08-29

·

Updated

2026-08-31

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHPGurukul Student Information System version 1.0
Description An issue exists in the /student edit1.php file where manipulating the ID argument allows for remote SQL injection. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.
Recommendations Update PHPGurukul Student Information System version 1.0 to a version that contains a fix for this issue. As a temporary workaround, restrict access to the /student edit1.php file to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82424

Affected Products

Phpgurukul Student Information System