Vendor
An unauthenticated remote SQL injection vulnerability in the Student-Management-System Login component allows attackers to execute arbitrary database commands via the loginCheckTest.php endpoint.