Sceawere

Vulnerability Detail

CVE-2026-90514UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in School Registration

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
4h ago
Vendor
SourceCodester
Product
School Registration and Fee System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-13T11:17:00.423Z",
  "pubdate": "2026-09-13T11:17:00.423Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified in the SourceCodester School Registration and Fee System 1.0.\nThe vulnerability exists within the /bilal/normal/save_stud.php file, specifically targeting the 'Status' argument.\nThis flaw allows remote, unauthenticated attackers to manipulate database queries, leading to unauthorized data exposure, modification, or potential administrative system compromise.\nThe exploit is publicly disclosed, significantly increasing the risk of active exploitation by malicious actors.\nOrganizations utilizing this software are at high risk of data breaches and integrity loss, necessitating immediate defensive action.",
  "technicalDetails": "The vulnerability originates from improper neutralization of special elements used in an SQL command within the /bilal/normal/save_stud.php script of the School Registration and Fee System 1.0.\nThe application fails to implement robust input validation or parameterized queries (prepared statements) for the 'Status' argument when processing student registration data.\nBy injecting malicious SQL syntax into the 'Status' parameter, an attacker can alter the logic of the backend database query executed by the application.\nThe attack flow involves the crafting of a malicious HTTP request directed at the vulnerable endpoint. Because the input is concatenated directly into the SQL statement, an attacker can terminate the intended query and append arbitrary SQL commands.\nThis behavior allows the attacker to execute unauthorized queries via the web application's database connection. Depending on the database configuration and application permissions, this could result in the exfiltration of sensitive student records, fee details, or authentication credentials.\nFurthermore, in environments where the database user possesses sufficient privileges, an attacker might be able to modify existing records, drop tables, or potentially escalate privileges within the underlying database management system.\nSince the vulnerability is exploitable remotely and does not explicitly require prior authentication to reach the vulnerable code path, it poses a severe threat to the confidentiality, integrity, and availability of the application's data. The disclosure of the exploit code in the public domain further lowers the barrier to entry for potential adversaries, allowing for automated scanning and mass exploitation of vulnerable instances."
}
CVE-2026-90514: SQL Injection in School Registration (HIGH Severity, CVSS: 7.3) | Sceawere