Description


A security flaw has been discovered in itsourcecode School Management System 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

References


https://github.com/ltranquility/CVE/issues/31

Issue TrackingExploitThird Party Advisory


https://vuldb.com/?ctiid.339331

Permissions RequiredVDB Entry

https://vuldb.com/?id.339331

Third Party AdvisoryVDB Entry

https://vuldb.com/?submit.728909

Third Party AdvisoryVDB Entry

Weaknesses



CWE-74CWE-89


CWE-89

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

7.3 · High

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-01-01T09:15:51.113Z

2 weeks ago

Last modified

2026-01-06T19:25:10.050Z

1 week ago