CVE-2020-35270

CRITICAL

Student Result Management System - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-35270. PoCs published by Ritesh Gohil.

AI-analyzed exploit summary This is a writeup describing an SQL injection vulnerability in the Student Result Management System 1.0, allowing authentication bypass via a specific payload in the login fields. No actual exploit code is provided.

Description

Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of Admin Panel and manage every account of Result.

Exploits (1)

exploitdb WRITEUP
by Ritesh Gohil · textwebappsmultiple
https://www.exploit-db.com/exploits/49152

This is a writeup describing an SQL injection vulnerability in the Student Result Management System 1.0, allowing authentication bypass via a specific payload in the login fields. No actual exploit code is provided.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Student Result Management System 1.0
No auth needed
Prerequisites: Access to the admin login portal
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/49152

Scores

CVSS v3 9.1
EPSS 0.0184
EPSS Percentile 76.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-89
Status published
Products (1)
student_result_management_system_project/student_result_management_system 1.0
Published Jan 26, 2021
Tracked Since Feb 18, 2026