CVE-2026-9469

A weakness has been identified in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. The impacted element is an unknown function of the file /success.php. This manipulation of the argument User causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Configurations

No configuration.

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una debilidad en yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. El elemento afectado es una función desconocida del archivo /success.PHP. Esta manipulación del argumento User causa inyección SQL. Es posible iniciar el ataque de forma remota. El exploit se ha puesto a disposición del público y podría usarse para ataques. Este producto está utilizando una versión continua para proporcionar entrega continua. Por lo tanto, no hay detalles de versión disponibles para las versiones afectadas ni actualizadas. El proyecto fue informado del problema temprano a través de un informe de problema, pero aún no ha respondido.

25 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-25 16:16

Updated : 2026-07-23 11:10


NVD link : CVE-2026-9469

Mitre link : CVE-2026-9469

CVE.ORG link : CVE-2026-9469


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')