Description
A vulnerability was identified in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/faculty/index.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
Published: 2026-01-29
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Immediate Patch
AI Analysis

Impact

A SQL injection flaw exists in the itsourcecode School Management System version 1.0, specifically in an undocumented function of the file /ramonsys/faculty/index.php. By manipulating the ID argument, an attacker can inject arbitrary SQL code and gain unauthorized read or write access to the underlying database. The vulnerability is exploitable remotely without authentication and is associated with CWE-89, indicating that input is not properly validated before incorporation into a query.

Affected Systems

The affected product is the itsourcecode School Management System, release 1.0, which is distributed under the vendor name itsourcecode. The flaw lies in the faculty index module of this application, and the associated CPE identifiers refer to this product and a similarly named product from angeljudesuarez, both at version 1.0.

Risk and Exploitability

The CVSS score of 6.9 signifies a moderate to high impact, while the EPSS score of less than 1% indicates a low likelihood of widespread exploitation at this time. The vulnerability is not listed in the KEV catalog, suggesting no evidence of known active exploits. An attacker can launch the attack remotely by constructing a crafted URL that alters the ID, and a publicly available exploit has been documented.

Generated by OpenCVE AI on April 18, 2026 at 01:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for the itsourcecode School Management System if one is available for version 1.0 or later.
  • If no patch exists, modify the application to sanitize or validate the ID parameter and use parameterized queries or prepared statements to prevent SQL injection.
  • Enforce strict access controls on the /ramonsys/faculty/index.php endpoint, ensuring only authorized users can reach it, and monitor logs for suspicious query patterns.

Generated by OpenCVE AI on April 18, 2026 at 01:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:itsourcecode:school_management_system:*:*:*:*:*:*:*:*

Mon, 02 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Angeljudesuarez
Angeljudesuarez school Management System
CPEs cpe:2.3:a:angeljudesuarez:school_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Angeljudesuarez
Angeljudesuarez school Management System

Fri, 30 Jan 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode school Management System
Vendors & Products Itsourcecode
Itsourcecode school Management System

Thu, 29 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 Jan 2026 14:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/faculty/index.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
Title itsourcecode School Management System index.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Angeljudesuarez School Management System
Itsourcecode School Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T09:04:32.379Z

Reserved: 2026-01-29T06:05:04.734Z

Link: CVE-2026-1590

cve-icon Vulnrichment

Updated: 2026-01-29T15:55:11.088Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-29T15:16:13.350

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-1590

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T01:30:16Z

Weaknesses