VENCERT-2026-019
CVE-2026-9470
Activa
Inyección SQL en StudentManagementSystem - función confirm_logged_in (student_trans.php)
Entrada no validada permite inyección SQL remota; posible lectura, alteración o borrado de datos en la base de la aplicación.
Sistemas afectados: yashpokharna2555 / StudentManagementSystem (commit cb2f558ddf8d19396de0f92abf2d224d46a0a203). Archivo student_trans.php, función confirm_logged_in; parámetros FIRST_NAME, Last_Name, EMAIL.