Impact
A SQL injection issue exists in the /ajax.php file of ITSourceCode's Fees Management System version 1.0. Manipulating the Username argument can cause arbitrary SQL commands to be executed. An attacker can exploit this flaw from a remote location, potentially compromising database contents or altering data.
Affected Systems
ITSourceCode’s Fees Management System, version 1.0 is affected by this vulnerability.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered remotely and has been publicly disclosed, suggesting that exploitability is realistic and attackers may attempt to leverage it.
OpenCVE Enrichment