Impact
The vulnerability resides in an unknown function within /ramonsys/enrollment/controller.php of itsourcecode Student Management System 1.0. An attacker can manipulate the ID argument to inject arbitrary SQL statements. This allows the attacker to read, modify or delete data stored in the underlying database, potentially exposing or corrupting sensitive student information. The weakness is a classic SQL injection flaw, reflected in CWEs 74 and 89, which can compromise confidentiality and integrity of the database.
Affected Systems
itsourcecode Student Management System version 1.0 is affected. The vulnerability is tied to the controller.php file in the enrollment module of this version. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, while the EPSS score of less than 1% suggests that the probability of exploitation at present is low. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed active exploitation. The attack can be carried out remotely by submitting a crafted ID parameter to the vulnerable endpoint, without the need for authentication or local access.
OpenCVE Enrichment