Impact
The University Management System version 1.0 contains a flaw in the view_result.php file that allows an attacker to inject arbitrary SQL through manipulation of the seme parameter. The injection is triggered by crafted input and can be performed remotely without local privileges. The vulnerability is classified as CWE-74 and CWE-89.
Affected Systems
The affected product is the University Management System provided by itsourcecode. The vulnerability is present in version 1.0 as indicated by the product name and the CPE string. No other versions are listed as affected.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate risk level. The EPSS score is less than 1%, suggesting the likelihood of exploitation is low. The vulnerability is not present in CISA’s KEV catalog. Because the exploit is publicly available, defenders should consider the potential for malicious exploitation, especially in environments where the application is exposed to the internet.
OpenCVE Enrichment