CVE-2026-105921: Kusalkasilva Learning-Management-System search_class.php sql injection
A vulnerability was identified in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. This affects an unknown function of the file searchclass.php. Such manipulation of the argument schoolyear leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attack is remote but requires low-level privileges. No user interaction is required.
Is there evidence that exploitation is practical?
Yes. A public exploit is available, and the attack complexity is rated low.
Are fixed releases available?
No affected or updated release versions are provided because the product uses a rolling-release model. The project was notified through an issue report but had not responded at the time of publication.