---
id: CVE-2026-82424
title: A weakness has been identified in PHPGurukul Student Information System 1.0
summary: >-
  A weakness has been identified in PHPGurukul Student Information System 1.0.
  Affected by this vulnerability is an unknown functionality of the file
  /student_edit1.php. Executing a manipulation of the argument ID can lead to
  sql injection…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
published: '2026-08-29'
updated: '2026-08-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82424'
references:
  - url: 'https://github.com/Bai-public/CVE/issues/8'
    label: cna@vuldb.com
  - url: 'https://phpgurukul.com/'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-82424'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/887957'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/887958'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/887959'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/397013'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/397013/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-08-30T13:53:03.068Z'
epss: 0.00341
epssPercentile: 0.24899
---

## Overview

A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /student_edit1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
