Description
A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/inquiry/index.php. This manipulation of the argument txtsearch causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-01-29
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Patch
AI Analysis

Impact

A vulnerability was identified in itsourcecode School Management System version 1.0 affecting the /ramonsys/inquiry/index.php file. The flaw stems from the improper handling of the txtsearch parameter, which can lead to arbitrary SQL statements being executed against the underlying database. This flaw permits the execution of injected SQL and can be triggered remotely by supplying malicious input in the txtsearch field. The vulnerability corresponds to the web script injection (CWE‑74) and SQL injection (CWE‑89) weaknesses.

Affected Systems

The School Management System from itsourcecode, version 1.0, is affected by the flaw in the inquiry module located under /ramonsys. No other versions or variants are listed in the available data.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity, while an EPSS score of less than 1% suggests a low probability of exploitation in the wild at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack can be initiated remotely, and an attacker could gain unauthorized database access or manipulate data stored in the system. The flaw is publicly disclosed, increasing the likelihood that CUI or sensitive data may be compromised if exploited.

Generated by OpenCVE AI on April 18, 2026 at 14:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an updated version of School Management System that addresses the SQL injection flaw, if such a release is available.
  • Ensure that the txtsearch input in /ramonsys/inquiry/index.php is sanitized or parameterized so that injected SQL cannot be executed.
  • Restrict access to the inquiry module by requiring authentication or by limiting the IP ranges that can reach the page through firewall or web‑server configuration.

Generated by OpenCVE AI on April 18, 2026 at 14:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:itsourcecode:school_management_system:*:*:*:*:*:*:*:*

Mon, 02 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Angeljudesuarez
Angeljudesuarez school Management System
CPEs cpe:2.3:a:angeljudesuarez:school_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Angeljudesuarez
Angeljudesuarez school Management System

Fri, 30 Jan 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode school Management System
Vendors & Products Itsourcecode
Itsourcecode school Management System

Thu, 29 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 Jan 2026 14:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/inquiry/index.php. This manipulation of the argument txtsearch causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Title itsourcecode School Management System index.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Angeljudesuarez School Management System
Itsourcecode School Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T09:04:20.529Z

Reserved: 2026-01-29T06:04:57.629Z

Link: CVE-2026-1589

cve-icon Vulnrichment

Updated: 2026-01-29T15:55:59.468Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-29T15:16:13.050

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-1589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T14:45:03Z

Weaknesses