Impact
The vulnerability resides in the User_Login.php file of version 1.0 of itsourcecode School Management System. An attacker can send a crafted email argument that is not properly sanitized, allowing arbitrary SQL code to be executed against the backend database. This flaw corresponds to CWE-74 and CWE-89 and is reported as a remote SQL injection capability.
Affected Systems
The affected system is the itsourcecode School Management System version 1.0, specifically the User_Login.php component used for user authentication.
Risk and Exploitability
The CVSS base score of 6.9 indicates a moderate severity and the vulnerability is publicly disclosed. No EPSS data is available, so the precise exploitation probability is unknown, and the issue is not listed in CISA KEV. The attack vector is remote, with the payload entering through the email field; any exposed instance of the application is therefore at risk and prompt remediation is advised.
OpenCVE Enrichment