Description
A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the file /ramonsys/soa/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
Published: 2026-02-06
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection leading to data compromise
Action: Patch Now
AI Analysis

Impact

A vulnerability exists in the itsourcecode Student Management System 1.0 within the file index.php. Manipulating the ID argument allows an attacker to inject arbitrary SQL, potentially enabling the reading, modification, or deletion of database contents. This flaw is categorized under CWE-74 and CWE-89.

Affected Systems

The affected product is itsourcecode Student Management System version 1.0. No other versions are explicitly mentioned, so any deployment of this version is at risk.

Risk and Exploitability

The CVSS score of 6.9 indicates medium severity. The EPSS score is less than 1%, implying a low likelihood of exploitation at this time, and the vulnerability is not currently listed in the CISA KEV catalog. Nonetheless, it can be launched remotely via the web interface by supplying a malicious ID value to the index.php endpoint. An attacker with network access to the web server can exploit it without additional authentication, making it a critical risk for exposed installations.

Generated by OpenCVE AI on April 18, 2026 at 18:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor's latest patch or upgrade to a patched version of the Student Management if available.
  • Restrict access to the application’s index.php to trusted IP ranges or internal networks using firewall or web server configuration.
  • Validate and sanitize all user-supplied ID parameters on the server side, using parameterized queries or prepared statements to eliminate unsanitized string concatenation.

Generated by OpenCVE AI on April 18, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 10 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode school Management System
CPEs cpe:2.3:a:itsourcecode:school_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Itsourcecode school Management System

Mon, 09 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Itsourcecode
Itsourcecode student Management System
Vendors & Products Itsourcecode
Itsourcecode student Management System

Fri, 06 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Feb 2026 09:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the file /ramonsys/soa/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
Title itsourcecode Student Management System index.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode School Management System Student Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T09:23:33.751Z

Reserved: 2026-02-05T19:28:32.574Z

Link: CVE-2026-2013

cve-icon Vulnrichment

Updated: 2026-02-06T15:01:53.638Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-06T10:16:07.967

Modified: 2026-02-10T18:13:22.703

Link: CVE-2026-2013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T18:30:07Z

Weaknesses