CVE-2026-5669 is a SQL injection vulnerability in the Cyber-III Student-Management-System affecting the /login.php file's Parameter Handler component, specifically through manipulation of the Password argument. The flaw allows remote attackers to inject malicious SQL queries without authentication, and proof-of-concept code has been publicly disclosed. Due to the project's rolling release model, specific version information is unavailable, though the vulnerability extends through commit 1a938fa61e9f735078e9b291d2e6215b4942af3f. The vulnerability carries a CVSS 3.1 score of 7.3 (High), with a network-based attack vector requiring low complexity and no user interaction or special privileges. This configuration indicates potential compromise of data confidentiality, integrity, and availability. The EPSS probability of exploitation is extremely low at 0.0004, suggesting this threat is not currently prioritized in active exploit campaigns. The exploit has been publicly disclosed and the vulnerability does not appear on the CISA Known Exploited Vulnerabilities list or Hot List, indicating no current evidence of active exploitation in the wild. However, the public availability of exploit code presents an ongoing risk. The project development team was notified early but has not responded, leaving affected organizations without an official patch and dependent on vendor mitigation efforts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cyber-III | Student-Management-System | 1a938fa61e9f735078e9b291d2e6215b4942af3fCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.