CVE-2026-18927
MEDIUMimranrisal-dev Student-Management-System Shared Upload Helper student_profile_pic.php storeProfileImage unrestricted upload
Title source: cnaDescription
A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. This affects the function storeProfileImage of the file student_profile_pic.php of the component Shared Upload Helper. Executing a manipulation of the argument choose_file can lead to unrestricted upload. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
References (5)
Core 5
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-386147 | imranrisal-dev Student-Management-System Shared Upload Helper student_profile_pic.php storeProfileImage unrestricted upload
https://vuldb.com/vuln/386147
Signature, Permissions Required signature
permissions-required
VDB-386147 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/386147/cti
Third Party Advisory third-party-advisory
CVE-2026-18927 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-18927
Third Party Advisory third-party-advisory
Submit #860103 | Student-Management-System imranrisal-dev 1/1 Command Injection
https://vuldb.com/submit/860103
Exploit exploit
issue-tracking
https://github.com/sanjibsajid381-ctrl/My-Web-cve/issues/1
Scores
CVSS v3
6.3
EPSS
0.0020
EPSS Percentile
10.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-284
CWE-434
Status
published
Products (2)
imranrisal-dev/Student-Management-System
18ea7904c339e0c7b0234724a79c939ce6191def
imranrisal-dev/Student-Management-System
a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c
Published
Aug 05, 2026
Tracked Since
Aug 05, 2026