CVE-2026-82620 | Soarkey StudentManagement/学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e CourseDao.java CourseDao.course_ranking cno sql injection (Issue 33)
A vulnerability identified as critical has been detected in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This affects the function CourseDao.course_ranking of the file code/src/dao/CourseDao.java. Performing a manipulation of the argument cno results in sql injection.
This vulnerability is cataloged as CVE-2026-82620. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.