Sceawere
Vulnerability Detail
CVE-2026-105920UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Kusalkasilva LMS SQL Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 11h ago
- Vendor
- Kusalkasilva
- Product
- Learning-Management-System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The impacted element is an unknown function of the file student_signup.php of the component Student Registration Endpoint. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-06T14:17:41.873Z",
"pubdate": "2026-10-06T14:17:41.873Z",
"executiveSummary": "A critical SQL injection vulnerability has been identified within the Kusalkasilva Learning-Management-System, specifically impacting the student_signup.php file. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary SQL commands by manipulating input parameters handled by the Student Registration Endpoint.\nThe vulnerability stems from improper neutralization of special elements used in SQL commands, which permits the injection of malicious SQL queries into the backend database. Successful exploitation grants an attacker the ability to bypass authentication mechanisms, gain unauthorized access to sensitive data, modify database contents, or potentially achieve full administrative compromise of the underlying database management system.\nGiven that the vulnerability is publicly disclosed and the project maintainers have not yet provided a resolution, the risk to affected deployments is high. The rolling release nature of the software makes identification of patched versions difficult, necessitating immediate manual inspection of the codebase to implement remediation measures.\nNo authentication is required to initiate the attack, making it reachable by any remote actor with network access to the target registration page. Organizations utilizing this software are advised to immediately restrict access to the affected endpoint or apply input validation controls until a formal security patch is released by the project maintainers.",
"technicalDetails": "The vulnerability resides in the Student Registration Endpoint of the Kusalkasilva Learning-Management-System, specifically within the logic implemented in student_signup.php. The flaw is categorized as a classic SQL Injection (SQLi), arising from the application's failure to properly sanitize or parameterize user-supplied input before incorporating it into database queries.\nTechnical analysis indicates that the application interface for student registration processes user-provided data directly into SQL statements without adequate input validation or the use of prepared statements. Consequently, an attacker can supply specially crafted strings containing SQL syntax characters (e.g., single quotes, comment delimiters, or union operators) to alter the intended query structure.\nThe attack flow begins with the adversary identifying the POST or GET parameters utilized by the student_signup.php script. By intercepting these requests, the attacker can append malicious SQL payloads. For instance, injecting a sequence such as ' OR 1=1 -- into a form field allows the attacker to manipulate the WHERE clause of a backend query. This effectively bypasses authentication, authenticates as an arbitrary user, or extracts information from other tables within the database schema.\nBecause the vulnerable element is a core registration function, it is inherently exposed to the network, requiring no prior authentication or administrative privileges to exploit. The lack of defensive coding practices—specifically the absence of prepared statements or parameterized queries—allows the database driver to interpret injected data as executable command code. This interpretation context allows for complex multi-statement queries, facilitating data exfiltration, deletion of records, or unauthorized modification of system settings.\nThe exploitability is compounded by the fact that the vulnerability has been publicly disclosed. Attackers utilize automated tools to scan for the vulnerable file path and trigger the injection, leading to high-impact post-exploitation scenarios, including full database compromise. As the software follows a rolling release model, there is no discrete version identifier to confirm if a fix has been integrated into the current build, requiring administrators to perform a manual review of the source code to verify the presence of input sanitization and secure database interaction patterns."
}