A security vulnerability has been detected in itsourcecode School Management System 1.0. This issue affects some unknown processing of the file /enrollment/index.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Due to contradicting product definitions in the original disclosure, this CVE was initially incorrectly assigned to the Student Management System.

Project Subscriptions

Vendors Products
Itsourcecode Subscribe
School Management System Subscribe
Student Management System Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 18 Feb 2026 06:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in itsourcecode Student Management System 1.0. This issue affects some unknown processing of the file /enrollment/index.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. A security vulnerability has been detected in itsourcecode School Management System 1.0. This issue affects some unknown processing of the file /enrollment/index.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Due to contradicting product definitions in the original disclosure, this CVE was initially incorrectly assigned to the Student Management System.
Title itsourcecode Student Management System index.php sql injection itsourcecode School Management System index.php sql injection

Fri, 13 Feb 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode school Management System
CPEs cpe:2.3:a:itsourcecode:student_management_system:1.0:*:*:*:*:*:*:* cpe:2.3:a:itsourcecode:school_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Itsourcecode school Management System

Tue, 10 Feb 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:itsourcecode:student_management_system:1.0:*:*:*:*:*:*:*

Tue, 03 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode student Management System
Vendors & Products Itsourcecode
Itsourcecode student Management System

Fri, 30 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 Jan 2026 17:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in itsourcecode Student Management System 1.0. This issue affects some unknown processing of the file /enrollment/index.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Title itsourcecode Student Management System index.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-18T05:33:59.011Z

Reserved: 2026-01-30T10:51:13.325Z

Link: CVE-2026-1701

cve-icon Vulnrichment

Updated: 2026-01-30T19:27:20.481Z

cve-icon NVD

Status : Modified

Published: 2026-01-30T18:15:59.727

Modified: 2026-02-18T06:16:34.687

Link: CVE-2026-1701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-02T09:27:27Z

Weaknesses