What is CVE-2026-19785?
A SQL injection vulnerability has been identified in the Student Medical Module of Francoisjacquet RosarioSIS up to version 12.7.4, specifically within the Medical.inc.php file. This flaw allows attackers to manipulate the 'table' argument, potentially leading to unauthorized database access; immediate update to the latest version is recommended.
Azərbaycanca: Francoisjacquet RosarioSIS-in 12.7.4 versiyasına qədər olan versiyalarında, Tələbə Tibbi Modulunda yerləşən Medical.inc.php faylındakı kod vasitəsilə SQL injection zəifliyi aşkar edilib. Bu, uzaqdan hücum edən şəxsə verilənlər bazasını manipulyasiya etməyə imkan verə bilər; dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of Francoisjacquet RosarioSIS are affected by CVE-2026-19785?
This SQL injection vulnerability affects Francoisjacquet RosarioSIS versions up to 12.7.4.
What can a remote attacker achieve by exploiting CVE-2026-19785?
A remote attacker can manipulate the database through this vulnerability, potentially leading to unauthorized database access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.