Back to Labs
Security Advisory

CVE-2021-26822

About

Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks.

Weakness (CWE):CWE-89

Rainforest analyst review

An unauthenticated SQL injection sits in the searchteacher POST parameter of PHPGurukul's Teachers Record Management System, in search-teacher.php. The advisory claims both sensitive-data leakage and code-execution potential, and the vector rates it unauthenticated with high impact across the board.

Unauthenticated SQLi in a small PHP application is trivially automated, and search endpoints are prime targets. That said, the code-execution claim deserves a measured read: turning SQLi into execution depends on database configuration and features like stacked queries or file writes being available, so data theft is the reliable outcome while RCE is conditional.

Apps like this almost never appear in a central inventory, so our angle is discovery and reachability, determining whether the software runs anywhere and whether the vulnerable endpoint is exposed to untrusted networks. We temper the top-line claim by distinguishing the near-certain data-leak risk from the situational code-execution one when we prioritize.

References

Related CVEs

Frequently asked questions

What is CVE-2021-26822?

Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks.

How severe is CVE-2021-26822?

CVE-2021-26822 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2021-26822 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2021-26822?

Public advisories list the following as affected: teachers record management system. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2021-26822?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email