Impact
unsanitized user credentials supplied to the login endpoint in /index.ph allow an attacker to inject arbitrary SQL code; the exploit can be launched remotely by anyone with network access to the web application, and the source code is publicly available, making replication straightforward. Successful exploitation could read, modify, or delete database records, resulting in confidentiality and integrity loss for the management system.
Affected Systems
the vulnerability affects the imvks786 Student Management System, as noted by the CNA vendor name, with all releases up to commit 9599b560ad3c3b83e75d328b76bedcd489ef1f46 potentially vulnerable. The project follows a rolling release model, so a specific fixed version is not yet identified; any deployment built before the fix remains at risk.
Risk and Exploitability
the CVSS score of 6.9 classifies the weakness as medium severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog; however, because exploitation is possible remotely and a public exploit already exists, the likelihood of real-world attacks remains significant. Attackers can achieve the SQL injection from any external host capable of reaching the application URL.
OpenCVE Enrichment