在 Kusalkasilva 学习管理系统(版本截至 ffeb873f8803f1e9664384ff75000c7da45466d2)中发现了一个安全漏洞。该漏洞影响文件 中的某个未知函数。通过对参数 的构造性操控,可导致 SQL 注入攻击。该攻击可由远程发起。目前相关利用代码已公开,存在被实际利用的风险。 该系统采用持续交付的滚动发布模式,因此受影响版本及修复后的版本均无具体版本号可供参考。项目方已通过问题报告(issue report)在早期获知此漏洞,但至今尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kusalkasilva | Learning-Management-System | ffeb873f8803f1e9664384ff75000c7da45466d2 |
cpe:2.3:a:kusalkasilva:learning-management-system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105918 | 7.3 HIGH | Kusalkasilva Learning-Management-System Login Endpoint login.php mysql_error sql injection |
| CVE-2026-105919 | 7.3 HIGH | Kusalkasilva Learning-Management-System Administrator Login Endpoint login.php mysql_query |
| CVE-2026-105920 | 7.3 HIGH | Kusalkasilva Learning-Management-System Student Registration Endpoint student_signup.php s |
No comments yet