← Vulnerability feed

Vulnerability record · CVE-2020-26051 · published 8 February 2021

CVE-2020-26051: College management system project college management system sql injection vulnerability

CCollege Management System Project · College Management System

College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters 'unametxt' and 'pwdtxt', which are not filtered before passing a SQL query.

9.8 CVSS 3.1 Critical EPSS 2.4% · top 16.6% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters 'unametxt' and 'pwdtxt', which are not filtered before passing a SQL query.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.exploit-db.com/exploits/48593 ExploitThird Party AdvisoryVDB Entry
https://www.exploit-db.com/exploits/48593 ExploitThird Party AdvisoryVDB Entry

Track CVE-2020-26051 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-39180College management system project college management system sql injection vulnerabilityCollege Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php pageEPSS 0.64%9.8CVE-2020-25409College management system project college management system sql injection vulnerabilityProjectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.EPSS 1.6%8.8CVE-2022-32420College management system project college management system vulnerabilityCollege Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /College/admin/teacher.php. This vulnerabili…EPSS 20%8.8CVE-2022-28079College management system project college management system sql injection vulnerabilityCollege Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.EPSS 29%7.2CVE-2022-39179College management system project college management system sql injection vulnerabilityCollege Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that ment…EPSS 1.1%7.2CVE-2022-30404College management system project college management system sql injection vulnerabilityCollege Management System v1.0 is vulnerable to SQL Injection via /College_Management_System/admin/display-teacher.php?teacher_id=.EPSS 0.80%6.9CVE-2024-7681College management system project college management system sql injection vulnerabilityA vulnerability was found in code-projects College Management System 1.0. It has been declared as critical. This vulnerability affects unknown code o…EPSS 0.73%6.5CVE-2020-25408College management system project college management system cross-site request forgery vulnerabilityA Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, …EPSS 0.78%

Source: NIST National Vulnerability Database (record CVE-2020-26051), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.