Impact
The vulnerability in the CourseDao.course_ranking function of Soarkey StudentManagement allows an attacker to manipulate the cno argument and inject arbitrary SQL. This flaw is a classic input sanitization weakness and can lead to unauthorized access, data exfiltration, or modification of the underlying database. The impact is limited to the data handled by the affected function but can enable broader investigations if the database contains additional sensitive information.
Affected Systems
Soarkey StudentManagement and the related Chinese-language name 学生信息管理系统 are affected. The version affected is any build up to commit e08f7f1d5015af407aa4cca0ada3dea189b4937e. No specific version numbers are listed beyond this commit reference, and the vulnerability is present in the Cloud source repository at https://github.com/Soarkey/StudentManagement.
Risk and Exploitability
The CVSS score of 5.3 places this issue in the moderate risk range. While the EPSS score is not available, the public release of an exploit suggests that attackers could deploy it quickly. The vulnerability can be reached remotely via the exposed CourseDao endpoint, and the project has not yet responded with a patch, increasing the window of exposure. It is not listed in the CISA KEV catalog, so it has not yet been observed in the wild at a large scale.
OpenCVE Enrichment