What is CVE-2026-18896?
This CVE identifies an SQL injection vulnerability in the `/student/changepass.php` file of lavkush-maurya Student-Registration-System 1.0. Remote attackers can manipulate the `oldpass` argument to execute arbitrary SQL commands. Mitigation requires immediate input validation and use of parameterized queries.
Azərbaycanca: Bu CVE, lavkush-maurya Student-Registration-System 1.0 proqramının `/student/changepass.php` faylında aşkar edilmiş SQL injection zəifliyidir. `oldpass` arqumentinin manipulyasiyası ilə uzaqdan hücum mümkündür. İstifadəçilər dərhal giriş yoxlamalarını gücləndirməli və parametrləşdirilmiş sorğulardan istifadə etməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which software and version is targeted in CVE-2026-18896?
lavkush-maurya Student-Registration-System 1.0.
Which argument is manipulated to exploit this SQL injection vulnerability?
The `oldpass` argument in the `/student/changepass.php` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.