Impact
A vulnerability exists in the itsourcecode Student Management System 1.0 within the file index.php. Manipulating the ID argument allows an attacker to inject arbitrary SQL, potentially enabling the reading, modification, or deletion of database contents. This flaw is categorized under CWE-74 and CWE-89.
Affected Systems
The affected product is itsourcecode Student Management System version 1.0. No other versions are explicitly mentioned, so any deployment of this version is at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. The EPSS score is less than 1%, implying a low likelihood of exploitation at this time, and the vulnerability is not currently listed in the CISA KEV catalog. Nonetheless, it can be launched remotely via the web interface by supplying a malicious ID value to the index.php endpoint. An attacker with network access to the web server can exploit it without additional authentication, making it a critical risk for exposed installations.
OpenCVE Enrichment