Sceawere

Vulnerability Detail

CVE-2026-105921UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in search_class.php

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
10h ago
Vendor
Kusalkasilva
Product
Learning-Management-System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. This affects an unknown function of the file search_class.php. Such manipulation of the argument school_year leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-06T15:17:17.497Z",
  "pubdate": "2026-10-06T15:17:17.497Z",
  "executiveSummary": "A SQL injection vulnerability exists in the Kusalkasilva Learning-Management-System, specifically within the search_class.php component. The vulnerability arises due to improper neutralization of input within the school_year parameter.\nThis flaw allows remote, unauthenticated attackers to execute arbitrary SQL commands against the backend database, potentially leading to unauthorized data disclosure, modification, or complete database compromise.\nThe product utilizes a rolling release model, meaning there are no specific version numbers; however, all deployments up to commit ffeb873f8803f1e9664384ff75000c7da45466d2 are confirmed to be vulnerable.\nThe project has been notified of the vulnerability but has not yet provided a patch. Given that exploit code is publicly available, the risk to organizations running this software is critical. Attackers can remotely exploit this vector without needing prior authentication or elevated privileges, making it a high-priority target for automated scanning and manual exploitation.",
  "technicalDetails": "The vulnerability is located in the search_class.php file of the Kusalkasilva Learning-Management-System. The root cause is an insecure implementation of database queries where user-supplied input provided through the school_year parameter is concatenated directly into SQL statements without adequate sanitization, validation, or the use of prepared statements.\nThe attack flow begins with a remote attacker sending a crafted HTTP request (typically a GET or POST request) to the search_class.php endpoint. By injecting malicious SQL syntax into the school_year argument, the attacker can manipulate the structure of the database query executed by the backend server.\nBecause the application fails to distinguish between legitimate user data and SQL commands, the database engine interprets the malicious input as part of the command itself. This enables the attacker to perform blind or error-based SQL injection, allowing them to enumerate database table schemas, extract sensitive records, or bypass authentication mechanisms that rely on underlying SQL queries.\nAffected systems remain vulnerable across all rolling release iterations up to commit ffeb873f8803f1e9664384ff75000c7da45466d2. Since the application does not employ strict input filtering or parameterization for the school_year variable, the attack surface is exposed directly to the network. An attacker can leverage publicly available exploit scripts to automate the data extraction process, significantly increasing the probability of successful exploitation.\nPost-exploitation impact is severe. Depending on the database user's privileges, an attacker might be able to read sensitive system files, modify administrative credentials, or delete entire datasets. Furthermore, if the database configuration is insecure, an attacker may leverage SQL injection to gain further persistence or perform lateral movement within the hosting environment. The absence of a vendor-provided patch leaves the system entirely reliant on compensating controls such as Web Application Firewalls (WAF) or manual code remediation by the administrator."
}
CVE-2026-105921: SQL Injection in search_class.php (MEDIUM Severity, CVSS: 6.3) | Sceawere