CVE-2026-5669General

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This vulnerability affects unknown code of the file /login.php of the component Parameter Handler. Such manipulation of the argument Password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Exploit: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-06); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-06: 1Mentions · 2026-04-28: 1PoC Mentioned / Linked · 2026-04-28: 1Technical Details · 2026-04-28: 104-0604-28
Signal classification2 categories
General
150.0%
Exploit
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-061
General1
2026-04-281
Exploit1
Full discourse2 posts
  • Giuseppe Paternicola@giuseppe_1337
    Exploit

    🚨 HIGH severity CVE-2026-5669 (CVSS 7.3): SQL injection in Cyber-III Student-Management-System /login[.]php. Remotely exploitable, no auth required. Exploit public. Patch status unknown. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/MtcYHjNmkt

    Post summary

    The tweet highlights a high‑severity SQL injection in Cyber‑III Student‑Management‑System with a publicly‑available exploit and no known patch.

    0000050
    27 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5669 A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This vulnerability affects unknown code of the fil… https://www.cve.org/CVERecord?id=CVE-2026-5669

    Post summary

    The text references CVE-2026-5669 for Cyber-III Student-Management-System but provides no details on exploitation, patches, or technical specifics.

    00000103
    57.0K followersView on X

Explore more