Impact
A SQL injection flaw exists in an unknown function of the file /ramonsys/facultyloading/index.php in itsourcecode Student Management System version 1.0. Manipulating the ID argument allows an attacker to inject arbitrary SQL, potentially leading to the disclosure or modification of sensitive data in the database. The weakness is identified by CWE-74 and CWE-89. The impact includes unauthorized data access or tampering, which could compromise the confidentiality, integrity, and availability of academic records. The documented exploitation technique requires remote interaction.
Affected Systems
The affected product is itsourcecode Student Management System, released as version 1.0. No other vendor or product variants are listed as impacted.
Risk and Exploitability
The vulnerability receives a CVSS v3.1 score of 6.9, indicating a medium severity assessment. The EPSS score is below 1%, suggesting a low probability of exploitation in the near term. The flaw is not recorded in the CISA KEV catalog. However, because the web application can be accessed remotely and the injection point is not protected by input validation, an attacker could potentially exploit the flaw from the internet if the system is exposed. No additional attack prerequisites or conditions are known from the public disclosure.
OpenCVE Enrichment