CyberRota Analysis
AI-GeneratedA critical SQL Injection vulnerability exists in StudIP versions 6.0.x prior to 6.0.3 and 5.4.x prior to 5.4.12, allowing remote attackers to execute arbitrary code and access sensitive information through the store() functions. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and data breaches. Immediate action is essential for those managing educational platforms or systems reliant on StudIP.
CVE
CVE-2026-51346
Severity
CRITICAL
CVSS
9.1
EPSS
0.52%
Original NVD Description
SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions.