Impact
The flaw resides in the unknown function of /course/index.php in itsourcecode School Management System 1.0, where manipulation of the ID argument can lead to an SQL injection that may be exploited remotely, allowing unauthorized data disclosure, tampering, or credential theft.
Affected Systems
Vendors impacted are itsourcecode with its School Management System version 1.0, and a related version 1.0 by Angel Judesuarez. All deployments of these products are vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog but public proof‑of‑concept exploits have been released, enabling attackers to leverage the remote SQL injection path if they can reach the vulnerable /course/index.php endpoint.
OpenCVE Enrichment