PatchSiren

StudIP CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL StudIP CVE published 2026-08-17

CVE-2026-51346

A SQL Injection vulnerability exists in StudIP versions 6.0.x before 6.0.3 and 5.4.x before 5.4.12. This vulnerability allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions. The CVSS score is 9.1, indicating a critical severity. Defenders responsible for StudIP installations, especially in environments where StudIP is used, should assess exposure and [truncated]