CVE-2026-5669

HIGH

Cyber-III Student-Management-System Parameter login.php sql injection

Title source: cna
STIX 2.1

Description

A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This vulnerability affects unknown code of the file /login.php of the component Parameter Handler. Such manipulation of the argument Password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-355491 | Cyber-III Student-Management-System Parameter login.php sql injection
https://vuldb.com/vuln/355491
Signature, Permissions Required signature permissions-required
VDB-355491 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/355491/cti
Third Party Advisory third-party-advisory
Submit #785942 | Cyber-III Student-Management-System 1.0 SQL Injection vulnerability
https://vuldb.com/submit/785942

Scores

CVSS v3 7.3
EPSS 0.0026
EPSS Percentile 17.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
Cyber-III/Student-Management-System 1a938fa61e9f735078e9b291d2e6215b4942af3f
Published Apr 06, 2026
Tracked Since Apr 06, 2026