What is CVE-2026-51346?
An SQL Injection vulnerability exists in older StudIP versions (6.0.x before 6.0.3 and 5.4.x before 5.4.12). A remote attacker can execute arbitrary code and obtain sensitive information via the store() functions. Immediate update to the patched versions is strongly recommended.
Azərbaycanca: Bu boşluq StudIP platformasının köhnə versiyalarında (6.0.3-dən əvvəl 6.0.x və 5.4.12-dən əvvəl 5.4.x) aşkarlanmış SQL Injection zəifliyidir. Uzaqdan hücum edən şəxs store() funksiyaları vasitəsilə özbaşına kod icra edə və həssas məlumatları əldə edə bilər. Təcili olaraq göstərilən versiyalara yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which StudIP versions are affected by CVE-2026-51346?
This vulnerability affects StudIP versions 6.0.x before 6.0.3 and 5.4.x before 5.4.12.
What can an attacker gain by exploiting CVE-2026-51346?
A remote attacker can execute arbitrary code and obtain sensitive information via the store() functions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.