Sceawere
Vulnerability Detail
CVE-2026-105918UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Kusalkasilva LMS SQL Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 13h ago
- Vendor
- Kusalkasilva
- Product
- Learning-Management-System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability has been found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. Impacted is the function mysql_error of the file login.php of the component Login Endpoint. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-06T12:16:47.287Z",
"pubdate": "2026-10-06T12:16:47.287Z",
"executiveSummary": "A critical SQL injection vulnerability has been identified in the Kusalkasilva Learning-Management-System login mechanism.\nThe vulnerability resides in the login.php file, specifically within the mysql_error function, which fails to properly sanitize user-supplied input.\nBy manipulating the 'username' or 'password' arguments, a remote, unauthenticated attacker can inject arbitrary SQL commands into the backend database query.\nSuccessful exploitation allows for unauthorized data extraction, manipulation of application state, or potential bypass of authentication controls.\nGiven that the application utilizes a continuous delivery model without distinct versioning, all instances using the affected commit hash (ffeb873f8803f1e9664384ff75000c7da45466d2) and prior iterations are considered vulnerable.\nThe vulnerability is currently public, and given the lack of vendor response, the risk of exploitation is elevated for exposed instances.",
"technicalDetails": "The vulnerability originates from the improper handling of user-controllable input within the authentication workflow in login.php.\nThe root cause is a failure to utilize parameterized queries or prepared statements when interacting with the MySQL database. Consequently, input provided through the 'username' or 'password' parameters is concatenated directly into the SQL command string before being executed.\nThe vulnerability is exacerbated by the use of mysql_error, which improperly processes or exposes error information derived from malformed SQL queries, aiding an attacker in reconnaissance.\nAttack Flow: 1. An attacker sends an HTTP POST request to the Login Endpoint containing a crafted payload within the 'username' or 'password' field. 2. The login.php script receives the raw input. 3. Because the input is not sanitized, the injected SQL syntax alters the intended logic of the authentication query (e.g., using 'OR 1=1' to force a successful evaluation). 4. The backend database executes the modified query, allowing the attacker to bypass authentication or extract sensitive information such as user credentials, hashed passwords, or configuration data.\nThe vulnerability is accessible remotely via the network, requiring no prior authentication or specific privileges to trigger the SQL injection. The impact is significant, as it can lead to full database compromise, including unauthorized read and write access to the underlying storage.\nBecause the project follows a continuous delivery release cycle, tracking specific versions is difficult, but the flaw is confirmed present up to commit ffeb873f8803f1e9664384ff75000c7da45466d2. Any authentication attempt is a potential vector for this exploit."
}