{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/kusalkasilva/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kusalkasilva:learning-management-system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-105918"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Learning-Management-System"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Kusalkasilva"],"content_html":"\u003cp\u003eThe Kusalkasilva Learning-Management-System is susceptible to a SQL injection vulnerability (CVE-2026-105918) within the mysql_error function located in the login.php file. This component handles the Login Endpoint for the application. Remote attackers can leverage this vulnerability by providing malicious input into the username or password parameters, enabling them to alter database queries. This flaw, which carries a CVSS v3.1 base score of 7.3, poses a significant risk as the exploit is publicly available. Because the project utilizes a continuous delivery model with rolling releases, no specific patched versions or version ranges are available; users should monitor the project repository for updates and maintain defense-in-depth controls around database access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to execute arbitrary SQL commands against the backend database. This may lead to unauthorized data exfiltration, modification of application records, or complete compromise of the learning management system's data integrity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to inspect and filter SQL injection payloads in the username and password parameters of login.php.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege to the database service account used by the Learning-Management-System to limit the potential impact of successful query manipulation.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual database error patterns or unexpected login attempts that deviate from standard user activity.\u003c/li\u003e\n\u003cli\u003eMonitor the Kusalkasilva Learning-Management-System source repository for commit notifications indicating a security fix for the mysql_error function.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T12:55:11Z","date_published":"2026-10-06T12:55:11Z","id":"https://feed.craftedsignal.io/briefs/2026-10-kusalkasilva-sqli/","summary":"A remote, unauthenticated SQL injection vulnerability in the login.php script of Kusalkasilva Learning-Management-System allows attackers to compromise database integrity.","title":"SQL Injection in Kusalkasilva Learning-Management-System Login Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-10-kusalkasilva-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Kusalkasilva","version":"https://jsonfeed.org/version/1.1"}