LOW
lavkush-maurya
CVE published 2026-08-05
CVE-2026-18896
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T02:16:37.593Z and has not been modified since then. A SQL injection vulnerability exists in the /student/changepass.php file of Student-Registration-System 1.0. The vulnerability is triggered by manipulating the oldpass argument. This issue allows for remote attacks and has been publicly disclose [truncated]