CVE-2026-10226

A flaw has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. Impacted is an unknown function of the file delete.php. Executing a manipulation of the argument user_id/course_id/teacher_id/student_id/application_id can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.
Configurations

No configuration.

History

22 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en raisulislamg4 student_management_system_by_PHP hasta 310d950e09013d5133c6b9210aff9444382d16d1. Se ve afectada una función desconocida del archivo delete.php. La ejecución de una manipulación del argumento user_id/course_id/teacher_id/student_id/application_id puede conducir a una inyección SQL. El ataque puede lanzarse de forma remota. El exploit ha sido publicado y puede usarse. Este producto opera bajo un modelo de lanzamiento continuo, asegurando la entrega continua. En consecuencia, no hay detalles de versión ni para las versiones afectadas ni para las actualizadas. Se informó al proyecto del problema con antelación a través de un informe de incidencias, pero aún no ha respondido.

01 Jun 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 06:16

Updated : 2026-07-22 07:10


NVD link : CVE-2026-10226

Mitre link : CVE-2026-10226

CVE.ORG link : CVE-2026-10226


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')