SQL Injection in Simple Student Information System
SourceCodester Simple Student Information System version 1.0 is vulnerable to remote SQL injection in the searchquery.php file, allowing unauthenticated attackers to manipulate database queries.
CVE search metadata
CVE search record: CVE-2026-105807. Severity: high. CVSS: 7.3. KEV: no. Product: Simple Student Information System (1.0). Brief: SQL Injection in Simple Student Information System. Brief link: https://feed.craftedsignal.io/briefs/2026-10-simple-student-sqli/
SourceCodester Simple Student Information System version 1.0 contains a SQL injection vulnerability within the searchquery.php script. The application fails to properly sanitize user-supplied input before incorporating it into database queries, allowing remote, unauthenticated attackers to inject arbitrary SQL commands. This vulnerability can lead to unauthorized data exfiltration, modification, or potential administrative bypass depending on the database configuration and permissions associated with the application's service account. Because the vulnerability is exploitable remotely, it presents a significant risk to organizations hosting this software in internet-facing environments.
Impact
Successful exploitation of this vulnerability allows unauthorized access to the underlying database. Depending on the environment, this may lead to the exposure of sensitive student records, compromise of user authentication credentials, or full application takeover.
Recommendation
Identify all instances of Simple Student Information System 1.0 in your environment. Since the vendor has not provided a patch as of the report date, implement strict input validation at the web application firewall (WAF) level to block SQL injection patterns targeting searchquery.php. Restrict access to the application to trusted internal networks until a remediation version is available.
Immediate actions
Deploy WAF rules to block SQL injection patterns targeting /searchquery.php
Mitigations
Restrict access to Simple Student Information System to trusted networks
CVE-2026-105807
Detection coverage 1
Detect CVE-2026-105807 Exploitation - SQL Injection in searchquery.php
highDetects potential SQL injection attempts against the vulnerable searchquery.php file
Detection queries are available on the platform. Get full rules →