Impact
A flaw in the file /admin/schoolyear.php of itsourcecode Online Admission System allows manipulation of the 'sy' argument to inject SQL statements. The injection can be performed from a remote location and is publicly available, giving an attacker the ability to read, modify, or delete data stored in the system’s database. This directly compromises the confidentiality and integrity of admission records and could be abused to elevate privileges or disrupt service.
Affected Systems
The vulnerability affects version 1.0 of itsourcecode Online Admission System. No other versions or variants are listed in the available data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS is not provided, but the exploit is publicly known and can be launched remotely, suggesting a realistic risk to unpatched systems. The system is not in the CISA KEV catalog. With CWE-74 and CWE-89 identifying string substitution and SQL injection weaknesses, an attacker can leverage unsanitised input to manipulate database queries.
OpenCVE Enrichment