Impact
The vulnerability resides in an unknown function within att_single_view.php of itsourcecode University Management System. By manipulating the dt argument, an attacker can inject arbitrary SQL statements. This flaw exposes a typical SQL injection weakness, allowing unauthorized reading, modification, or deletion of database records depending on the underlying database privileges. The impact is therefore loss of data confidentiality and integrity.
Affected Systems
Itsourcecode University Management System version 1.0 is affected. No other versions are reported as vulnerable. The risk is confined to installations of this product that expose the att_single_view.php endpoint.
Risk and Exploitability
The CVSS score of 6.9 classifies the vulnerability as medium severity, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The flaw is exploitable remotely, and publicly available exploits exist, meaning an attacker could trigger the injection from anywhere with network access to the application. The vulnerability is not listed in the CISA KEV catalog at this time, but its remote nature and available exploitation code elevate its relevance to administrators.
OpenCVE Enrichment