CVE-2026-3744

Plain English Summary

AI-powered analysis for quick understanding

An attacker can remotely manipulate a specific part of the student web portal's signup process to execute unauthorized SQL commands, potentially gaining access to sensitive data in the database. This vulnerability occurs when the system improperly handles user input during password validation, making it easier for attackers to exploit.

Technical Description

A vulnerability has been found in code-projects Student Web Portal 1.0. This impacts the function valreg_passwdation of the file signup.php. The manipulation of the argument reg_passwd leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeChanged

Vector String

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$1,000($500-$1K)
Vendor Response
Grade APatched in 1 day

Quick Information

Published

Mar 8, 2026

about 1 month ago

Last Modified

Mar 9, 2026

29 days ago

Vendor

carmelo

Product

student web portal

Related Vulnerabilities

CVE-2026-3763Medium

This vulnerability allows an attacker to inject malicious scripts into the Simple Flight Ticket Booking System, potentially stealing sensitive information from users who visit the affected page. The attack can be carried out remotely, meaning the attacker doesn't need direct access to the system to exploit it.

CVE-2026-3745Medium

An attacker can exploit a vulnerability in the student web portal to manipulate user data and execute unauthorized SQL commands, potentially gaining access to sensitive information in the database. This attack can be carried out remotely, meaning the attacker does not need physical access to the system, and the exploit details are publicly available.

CVE-2026-3736Medium

An attacker can remotely manipulate a search query in the Simple Flight Ticket Booking System, allowing them to execute unauthorized SQL commands and potentially access or alter sensitive data in the database. This vulnerability occurs due to improper handling of user input in the SearchResultRoundtrip.php file.

CVE-2026-3735Medium

This vulnerability allows an attacker to remotely manipulate a specific part of the flight booking system to execute unauthorized SQL commands, potentially exposing or altering sensitive data in the database. The issue arises from improper handling of user input in the SearchResultOneway.php file, making it crucial for system administrators to patch this flaw to prevent exploitation.

CVE-2026-3723Medium

This vulnerability allows an attacker to manipulate the flight number in the booking system, potentially gaining unauthorized access to the database and extracting sensitive information. The attack can be carried out remotely, meaning the attacker doesn't need to be on the same network as the system to exploit it.