Impact
The vulnerability in itsourcecode College Management System 1.0 allows an attacker to inject arbitrary SQL code via the Search parameter in the /admin/search_student.php endpoint. This flaw is classified as a classic SQL injection (CWE‑89) with additional unvalidated input handling (CWE‑74). An attacker can use the injection to read, modify, or delete data from the database, potentially exposing sensitive student information or disrupting the system's integrity.
Affected Systems
Affected is the College Management System from vendor itsourcecode, version 1.0. No additional sub‑versions are specified; all instances of the 1.0 release that include the /admin/search_student.php file are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the vulnerability can be exploited remotely without any local access. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is publicly disclosed, attackers are likely to target any exposed instance of the vulnerable endpoint using simple injection payloads. The risk to confidentiality and integrity is significant, though availability impact is not explicitly reported.
OpenCVE Enrichment