Impact
A flaw in itsourcecode Fees Management System 1.0 allows an attacker to manipulate the ID argument in the manage_student.php script, resulting in a SQL injection that can be executed remotely. This could enable the unauthorized extraction or alteration of database contents, potentially exposing sensitive student information or compromising the system integrity. The vulnerability description explicitly states it is remotely exploitable and publicly available.
Affected Systems
The affected product is the Fees Management System from itsourcecode, version 1.0. Only this version is explicitly identified; no other versions are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact combined with a potential remote attack vector. EPSS data are not available, but the presence of a public exploit suggests that attacks are feasible. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed widespread exploitation yet. An attacker likely triggers the injection through a crafted HTTP request targeting the ID parameter on the web interface.
OpenCVE Enrichment