Impact
A SQL injection flaw exists in the Dashboard component of the sambitraj Student‑Management‑System. The flaw allows an attacker to inject arbitrary SQL through the roll_no and teacher_name parameters, potentially enabling unauthorized access to, modification of, or exfiltration of database contents. The underlying weakness is a failure to properly validate or escape user input, as categorized by CWE‑74 and CWE‑89.
Affected Systems
The affected product is sambitraj: Student‑Management‑System, specifically the Dashboard functionality. No specific release is known to be fixed, as the project follows a rolling release model and current version identifiers are unavailable. The vulnerability applies to all versions up to the commit containing the reported flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploits in the wild. The attack vector is remote, meaning anyone who can send HTTP requests to the damaged endpoint may exploit the flaw. Without an official patch, the risk remains open as the vulnerability is publicly documented and could be leveraged by attackers attempting to compromise confidential student data.
OpenCVE Enrichment