<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:kusalkasilva:learning-Management-System:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3akusalkasilvalearning-management-system/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 12:55:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3akusalkasilvalearning-management-system/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection in Kusalkasilva Learning-Management-System Login Endpoint</title><link>https://feed.craftedsignal.io/briefs/2026-10-kusalkasilva-sqli/</link><pubDate>Tue, 06 Oct 2026 12:55:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-kusalkasilva-sqli/</guid><description>A remote, unauthenticated SQL injection vulnerability in the login.php script of Kusalkasilva Learning-Management-System allows attackers to compromise database integrity.</description><content:encoded><![CDATA[<p>The Kusalkasilva Learning-Management-System is susceptible to a SQL injection vulnerability (CVE-2026-105918) within the mysql_error function located in the login.php file. This component handles the Login Endpoint for the application. Remote attackers can leverage this vulnerability by providing malicious input into the username or password parameters, enabling them to alter database queries. This flaw, which carries a CVSS v3.1 base score of 7.3, poses a significant risk as the exploit is publicly available. Because the project utilizes a continuous delivery model with rolling releases, no specific patched versions or version ranges are available; users should monitor the project repository for updates and maintain defense-in-depth controls around database access.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated remote attacker to execute arbitrary SQL commands against the backend database. This may lead to unauthorized data exfiltration, modification of application records, or complete compromise of the learning management system's data integrity.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Implement web application firewall (WAF) rules to inspect and filter SQL injection payloads in the username and password parameters of login.php.</li>
<li>Apply the principle of least privilege to the database service account used by the Learning-Management-System to limit the potential impact of successful query manipulation.</li>
<li>Monitor logs for unusual database error patterns or unexpected login attempts that deviate from standard user activity.</li>
<li>Monitor the Kusalkasilva Learning-Management-System source repository for commit notifications indicating a security fix for the mysql_error function.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>