CVE-2026-18896: lavkush-maurya Student-Registration-System changepass.php sql injection
A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.php. Executing a manipulation of the argument oldpass can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18896?
The severity of CVE-2026-18896 is rated as medium with a score of 6.3.
How do I fix CVE-2026-18896?
To fix CVE-2026-18896, it is recommended to implement proper input validation and prepared statements to prevent SQL injection.
What type of vulnerability is CVE-2026-18896?
CVE-2026-18896 is classified as an SQL Injection vulnerability.
Can CVE-2026-18896 be exploited remotely?
Yes, CVE-2026-18896 can be exploited remotely by manipulating the oldpass argument.
Which file is affected by CVE-2026-18896?
The affected file in CVE-2026-18896 is /student/changepass.php.