{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aitsourcecodeschool_management_system1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:itsourcecode:school_management_system:1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-86268"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["School Management System (1.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["itsourcecode"],"content_html":"\u003cp\u003eitsourcecode School Management System version 1.0 contains a critical SQL injection vulnerability identified as CVE-2026-86268. The vulnerability resides within the User_Login.php file, specifically involving insufficient input validation of the 'email' argument. An unauthenticated remote attacker can exploit this flaw by submitting a specially crafted SQL payload via the email parameter to trigger unauthorized database operations. Given the public availability of the exploit code, organizations utilizing this software are at significant risk of database compromise, including unauthorized data exfiltration or potential administrative takeover. The vulnerability has been assigned a CVSS v3.1 base score of 7.3.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to execute arbitrary SQL commands against the backend database. This may lead to the disclosure of sensitive user information, modification of application records, or complete compromise of the School Management System data store.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of itsourcecode School Management System 1.0 within the environment.\u003c/li\u003e\n\u003cli\u003ePatch or disable the affected School Management System software immediately as no vendor fix is currently specified.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) to block suspicious POST requests to User_Login.php containing SQL syntax characters such as single quotes, double dashes, or UNION/SELECT keywords.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T04:50:12Z","date_published":"2026-09-07T04:50:12Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86268-sqli/","summary":"CVE-2026-86268 is an unauthenticated SQL injection vulnerability in itsourcecode School Management System 1.0, allowing remote command execution via the email parameter.","title":"SQL Injection in School Management System 1.0 via User_Login.php","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86268-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:itsourcecode:school_management_system:1.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}