Impact
A flaw was discovered in itsourcecode School Management System version 1.0, in an unknown area of the file /ramonsys/settings/controller.php. Manipulating the ID argument permits SQL injection, which can reveal or alter database contents and compromise data confidentiality and integrity due to the CWE-74 and CWE-89 weaknesses.
Affected Systems
The vulnerability affects itsourcecode School Management System, specifically the 1.0 release. Administrators of installations running this version should consider that the /controller.php component is compromised.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium‑to‑high risk, while the EPSS score of less than 1% shows a low but non‑zero probability of exploitation. The vulnerability is not listed in KEV. Attackers can remotely trigger the injection by manipulating the ID parameter, as the exploit is publicly available. Given the data, the risk is moderate but the impact could be significant if a database compromise occurs.
OpenCVE Enrichment