Impact
A SQL injection flaw exists in the itsourcecode School Management System version 1.0, specifically in an undocumented function of the file /ramonsys/faculty/index.php. By manipulating the ID argument, an attacker can inject arbitrary SQL code and gain unauthorized read or write access to the underlying database. The vulnerability is exploitable remotely without authentication and is associated with CWE-89, indicating that input is not properly validated before incorporation into a query.
Affected Systems
The affected product is the itsourcecode School Management System, release 1.0, which is distributed under the vendor name itsourcecode. The flaw lies in the faculty index module of this application, and the associated CPE identifiers refer to this product and a similarly named product from angeljudesuarez, both at version 1.0.
Risk and Exploitability
The CVSS score of 6.9 signifies a moderate to high impact, while the EPSS score of less than 1% indicates a low likelihood of widespread exploitation at this time. The vulnerability is not listed in the KEV catalog, suggesting no evidence of known active exploits. An attacker can launch the attack remotely by constructing a crafted URL that alters the ID, and a publicly available exploit has been documented.
OpenCVE Enrichment