Impact
An unknown component of itsourcecode School Management System 1.0 contains a vulnerability in the controller.php file that allows an attacker to manipulate the ID argument and inject arbitrary SQL statements. The flaw is classified as CWE-74 and CWE-89 and enables the attacker to execute the injected SQL remotely, potentially reading, modifying or deleting sensitive data in the database, and escalating privileges if the database user has high permissions.
Affected Systems
The affected system is itsourcecode School Management System version 1.0. No other versions were explicitly listed as impacted. The vulnerability resides in the /ramonsys/course/controller.php file of this product.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, but the public availability of an exploit means that attackers could target the system if it is not patched. Attackers would need to send a crafted request to the application’s ID parameter from a remote location to trigger the injection.
OpenCVE Enrichment