CVE-2024-55270

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to manipulate the database of the student management system by injecting harmful SQL code through the searchdata parameter, potentially exposing sensitive information or altering data. To exploit this, the attacker needs access to the search feature on the admin page.

Technical Description

phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$4,789($1K-$5K)
Vendor Response
Grade APatched in 5 days

Quick Information

Published

Feb 17, 2026

about 2 months ago

Last Modified

Feb 23, 2026

about 1 month ago

Vendor

phpgurukul

Product

student management system