CVE-2026-86518: code-projects Student Crud Operation edit.php sql injection
Published Sep 8, 2026
·Updated
A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
0 affected components
Event History
Sep 8, 2026
CVE Published
via MITRE·03:45 AM
Data Sourced
via MITRE·03:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The severity vector indicates that an attacker needs low-level privileges (PR:L). Exploitation can be initiated remotely and does not require user interaction.
2
How serious is the potential impact?
The supplied CVSS vector rates confidentiality, integrity, and availability impact as low. Successful SQL injection could therefore affect each of those security properties at a limited level.
3
Is public exploit information available?
Yes. The vulnerability description states that an exploit has been publicly disclosed and may be used.