---
id: CVE-2026-105807
title: SourceCodester Simple Student Information System searchquery.php sql injection
summary: >-
  A vulnerability was found in SourceCodester Simple Student Information System
  1.0. This affects an unknown part of the file searchquery.php. Performing a
  manipulation results in sql injection. The attack can be initiated remotely.
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'
cvssSource: cna
cwe:
  - CWE-89
  - CWE-74
vendor: SourceCodester
product: Simple Student Information System
affected:
  - simple_student_information_system 1.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T07:30:14.194Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-105807'
references:
  - url: 'https://vuldb.com/vuln/413812'
    label: >-
      VDB-413812 | SourceCodester Simple Student Information System
      searchquery.php sql injection
  - url: 'https://vuldb.com/vuln/413812/cti'
    label: 'VDB-413812 | CTI Indicators (IOB, IOC, TTP, IOA)'
  - url: 'https://vuldb.com/cve/CVE-2026-105807'
    label: CVE-2026-105807 | CVE Analysis and Report
  - url: 'https://vuldb.com/submit/992606'
    label: >-
      Submit #992606 | SourceCodester Simple Student Information System 1.0 SQL
      Injection
  - url: 'https://github.com/lshhhhh318/cve/issues/1'
  - url: 'https://www.sourcecodester.com/'
tags:
  - cve.org
ingestedAt: '2026-10-06T07:49:23.046Z'
---

## Overview

A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an unknown part of the file searchquery.php. Performing a manipulation results in sql injection. The attack can be initiated remotely.

## Affected

- `simple_student_information_system 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
