CVE-2026-10110: code-projects Student Details Management System index.php sql injection

Published May 30, 2026
·
Updated

A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument roll results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

Affected Software

1 affected component
Code-projects Student Details Management System=1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove code-projects Student Details Management System 1.0 from your environment.

    If the application is not required, uninstall or remove the Student Details Management System instance (take the site offline) until a secure, patched version is available.

  2. Configuration

    Modify /index.php to stop interpolating the 'roll' parameter into SQL. Use parameterized queries (prepared statements) for all database access and enforce strict validation/sanitization of the 'roll' parameter (e.g., allow only expected numeric or fixed-format values).

    code-projects Student Details Management System (index.php) roll parameter handling = use prepared statements and strict input validation
  3. Compensating control

    Deploy WAF or application-layer filters to block SQL injection patterns targeting the 'roll' parameter, restrict access to the vulnerable endpoint to trusted IPs where possible, and apply rate-limiting and monitoring on requests to /index.php.

  4. Operational

    Assume possible exploitation given public availability of an exploit: review web and database logs for suspicious requests involving the 'roll' parameter, rotate database credentials and any potentially exposed secrets, and review accounts and privileges for signs of compromise.

Event History

May 30, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Feb 4, 58380
Event
via NVD·07:37 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-10110?

CVE-2026-10110 has a severity rating of high at 7.3.

2

How do I fix CVE-2026-10110?

To fix CVE-2026-10110, validate and sanitize user inputs to prevent SQL injection.

3

What type of vulnerability is CVE-2026-10110?

CVE-2026-10110 is classified as an SQL injection vulnerability.

4

Can CVE-2026-10110 be exploited remotely?

Yes, CVE-2026-10110 can be exploited remotely by manipulating the argument 'roll'.

5

Which software does CVE-2026-10110 affect?

CVE-2026-10110 affects Code-projects Student Details Management System version 1.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203