A vulnerability described as critical has been identified in StudIP up to 6.0.2/5.4.11. Affected is the function store. The manipulation results in sql injection.

This vulnerability was named CVE-2026-51346. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.