CVE-2026-2171
HIGHFabian Online Student Management System - Injection
Title source: ruleDescription
A vulnerability was found in code-projects Online Student Management System 1.0. Affected is an unknown function of the file accounts.php of the component Login. Performing a manipulation of the argument username/password results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
References (5)
Scores
CVSS v3
7.3
EPSS
0.0001
EPSS Percentile
1.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-74
CWE-89
Status
published
Affected Products (1)
fabian/online_student_management_system
Timeline
Published
Feb 08, 2026
Tracked Since
Feb 18, 2026