Impact
The affected component is the /att_add.php file of itsourcecode University Management System 1.0, where manipulating the Name argument leads to an SQL injection vulnerability. An attacker can introduce arbitrary SQL statements, enabling unauthorized reading or modification of the university’s database. This poses a risk to confidentiality and integrity; the vulnerability is flagged as a remote attack, meaning it can be triggered from outside the network.
Affected Systems
The vulnerability affects the University Management System version 1.0 produced by itsourcecode. The Common Platform Enumeration provided confirms the scope of the affected product: cpe:2.3:a:angeljudesuarez:university_management_system:1.0:*:*:*:*:*:*:*.
Risk and Exploitability
The CVSS score is 6.9, indicating medium severity. The EPSS score is reported as < 1%, suggesting a low likelihood of active exploitation at any given time. The vulnerability is not listed in the CISA KEV catalog. Because the attack may be initiated remotely and the exploit has been publicly disclosed, the risk remains significant if the system remains unpatched. No additional exploit prerequisites are detailed in the provided data.
OpenCVE Enrichment