What is CVE-2026-18927?
A vulnerability was found in the imranrisal-dev Student-Management-System, specifically within the `storeProfileImage` function in `student_profile_pic.php` of the Shared Upload Helper component. This flaw may allow remote code execution (RCE), posing a critical risk. Immediate remediation requires updating or disabling the affected component.
Azərbaycanca: imranrisal-dev Student-Management-System lövhəsində, xüsusilə `student_profile_pic.php` faylındakı `storeProfileImage` funksiyasında zəiflik aşkar edilib. Uzaqdan kod icrasına (RCE) imkan verə bilən bu problem, sistemi hücumlara qarşı həssas edir. Təhlükəsizlik üçün dərhal təsirlənən komponent yenilənməli və ya əlil edilməlidir.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which file contains the CVE-2026-18927 vulnerability in the imranrisal-dev Student-Management-System?
The vulnerability is located in the `storeProfileImage` function within the `student_profile_pic.php` file.
What type of threat can the CVE-2026-18927 vulnerability lead to?
This flaw may allow remote code execution (RCE).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.