SQL Injection in Kusalkasilva Learning-Management-System Login Endpoint
A remote, unauthenticated SQL injection vulnerability in the login.php script of Kusalkasilva Learning-Management-System allows attackers to compromise database integrity.
CVE search metadata
CVE search record: CVE-2026-105918. Severity: high. CVSS: 7.3. KEV: no. Product: Learning-Management-System. Brief: SQL Injection in Kusalkasilva Learning-Management-System Login Endpoint. Brief link: https://feed.craftedsignal.io/briefs/2026-10-kusalkasilva-sqli/
The Kusalkasilva Learning-Management-System is susceptible to a SQL injection vulnerability (CVE-2026-105918) within the mysql_error function located in the login.php file. This component handles the Login Endpoint for the application. Remote attackers can leverage this vulnerability by providing malicious input into the username or password parameters, enabling them to alter database queries. This flaw, which carries a CVSS v3.1 base score of 7.3, poses a significant risk as the exploit is publicly available. Because the project utilizes a continuous delivery model with rolling releases, no specific patched versions or version ranges are available; users should monitor the project repository for updates and maintain defense-in-depth controls around database access.
Impact
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary SQL commands against the backend database. This may lead to unauthorized data exfiltration, modification of application records, or complete compromise of the learning management system's data integrity.
Recommendation
- Implement web application firewall (WAF) rules to inspect and filter SQL injection payloads in the username and password parameters of login.php.
- Apply the principle of least privilege to the database service account used by the Learning-Management-System to limit the potential impact of successful query manipulation.
- Monitor logs for unusual database error patterns or unexpected login attempts that deviate from standard user activity.
- Monitor the Kusalkasilva Learning-Management-System source repository for commit notifications indicating a security fix for the mysql_error function.
Immediate actions
Deploy WAF rules to sanitize username and password input
Threat Hunt
Search web logs for high frequency of login errors or unusual SQL characters in login requests
Data: webserver access logs
Mitigations
Monitor project repository for software update to address the mysql_error function
CVE-2026-105918
Detection coverage 1
Detect CVE-2026-105918 Exploitation - SQL Injection in Login Endpoint
highDetects attempted SQL injection via the username or password parameter in the login.php endpoint.
Detection queries are available on the platform. Get full rules →