#Education Software
All CosmicBytez Labs articles tagged #Education Software, across news, security advisories, how-to guides, and projects.
- Security
SQL Injection in SourceCodester School Registration and Fee System 1.0
CVE-2026-90514 lets unauthenticated remote attackers inject SQL via the Status parameter in save_stud.php, with a public PoC exploit already live.
- Security
CVE-2025-67403: Critical SQL Injection in CASAP Enrollment System update_class.php
A critical-severity SQL injection vulnerability (CVSS 9.8) in Sourcecodester CASAP Automated Enrollment System 1.0 allows unauthenticated remote attackers...
- Security
CVE-2025-67404: Critical SQL Injection in CASAP Enrollment System save_stud.php
A critical-severity SQL injection vulnerability (CVSS 9.8) in Sourcecodester CASAP Automated Enrollment System 1.0 allows unauthenticated attackers to...
- Security
CVE-2026-11334: SQL Injection in College Management System
A high-severity SQL injection vulnerability (CVSS 7.3) in CollegeManagementSystem allows attackers to manipulate the department_code parameter in…
- Security
CVE-2026-41588: RELATE Courseware Timing Attack in Authentication (CVSS 9.0)
A timing attack vulnerability in RELATE's check_sign_in_key() function could allow attackers to infer valid sign-in keys through response time differences...