Sceawere

Vulnerability Detail

CVE-2026-105919UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Kusalkasilva LMS

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
12h ago
Vendor
Kusalkasilva
Product
Learning-Management-System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The affected element is the function mysql_query of the file admin/login.php of the component Administrator Login Endpoint. The manipulation of the argument username/password results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-06T13:16:47.120Z",
  "pubdate": "2026-10-06T13:16:47.120Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified within the Kusalkasilva Learning-Management-System, specifically impacting the administrative login endpoint.\nThe vulnerability resides in the admin/login.php file, where user-supplied input for authentication credentials is not properly sanitized before being processed by the mysql_query function.\nThis flaw allows remote, unauthenticated attackers to manipulate SQL queries, potentially bypassing authentication, extracting sensitive database information, or executing administrative actions.\nGiven that the vulnerability is publicly disclosed and the vendor has not provided a patch, the risk level is high, necessitating immediate defensive measures to secure the administrative interface.",
  "technicalDetails": "The vulnerability originates from improper neutralization of special elements used in an SQL command within the admin/login.php component of the Kusalkasilva Learning-Management-System. Specifically, the application utilizes the mysql_query function to execute database queries constructed directly from user input provided in the username and password fields without adequate parameterization or escaping mechanisms.\nThe root cause is the reliance on unsanitized user-controllable input in a dynamic SQL statement. By injecting crafted SQL sequences into the authentication parameters, an attacker can alter the logic of the backend SQL query. For instance, injecting characters such as a single quote (') or SQL comment operators (e.g., -- or #) allows an attacker to terminate the intended query structure and append malicious commands.\nThe attack flow proceeds as follows: First, the attacker navigates to the administrative login endpoint. Second, the attacker inputs malicious SQL payloads into the 'username' or 'password' fields. Third, the backend script concatenates these inputs directly into an SQL query string intended to verify credentials. Fourth, the database executes the modified query, which may result in an authentication bypass if the attacker forces the condition to evaluate to true (e.g., 'OR 1=1--).\nBecause the application performs direct concatenation, this vulnerability is susceptible to both error-based and boolean-based blind SQL injection techniques. An attacker can leverage this access to perform data exfiltration, including the extraction of administrator hashes or personal information stored within the underlying database. Furthermore, depending on the database configuration and permissions of the application's database user, this flaw could potentially lead to data modification, deletion, or full system compromise.\nThe vulnerability is remotely exploitable without requiring prior authentication, significantly lowering the barrier to entry for adversaries. As the project lacks formal versioning, all installations up to the commit hash ffeb873f8803f1e9664384ff75000c7da45466d2 are considered affected."
}
CVE-2026-105919: SQL Injection in Kusalkasilva LMS (HIGH Severity, CVSS: 7.3) | Sceawere