A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index.php. This manipulation of the argument eid/did causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
CVE-2026-10620 is a SQL injection vulnerability in code-projects Student Admission System 1.0 affecting the /index.php file through the eid/did parameters. Remote attackers can exploit this publicly disclosed flaw to manipulate database queries without authentication.
ثغرة حقن SQL في نظام القبول الجامعي الإصدار 1.0 تؤثر على ملف /index.php من خلال معاملات eid و did. يمكن للمهاجمين البعيدين استغلال هذه الثغرة المعروفة علناً لتنفيذ أوامر SQL عشوائية والوصول إلى بيانات الطلاب والمؤسسات.
A SQL injection vulnerability exists in Student Admission System 1.0 that allows remote attackers to execute arbitrary SQL commands through the eid/did parameters in /index.php. The vulnerability has been publicly disclosed and poses a significant risk to educational institutions using this system.
Immediately upgrade Student Admission System to a patched version if available. Implement input validation and parameterized queries for all database operations. Apply Web Application Firewall (WAF) rules to block SQL injection patterns. Conduct security audit of all database-connected forms and disable the vulnerable system until patched.
قم بترقية نظام القبول الجامعي إلى نسخة معدلة فوراً. طبق التحقق من صحة المدخلات والاستعلامات المعاملة لجميع عمليات قاعدة البيانات. طبق قواعد جدار الحماية لتطبيقات الويب لحجب أنماط حقن SQL. أجرِ تدقيقاً أمنياً شاملاً وعطّل النظام حتى يتم إصلاحه.