Description
A vulnerability has been found in itsourcecode Student Information System 1.0. This affects an unknown part of the file /section_edit1.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Problem types
Product status
Timeline
| 2025-12-07: | Advisory disclosed |
| 2025-12-07: | VulDB entry created |
| 2025-12-07: | VulDB entry last update |
Credits
yhbys (VulDB User)
References
vuldb.com/?id.334656 (VDB-334656 | itsourcecode Student Information System section_edit1.php sql injection)
vuldb.com/?ctiid.334656 (VDB-334656 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.700986 (Submit #700986 | itsourcecode Student Information System V1.0 SQL Injection)
vuldb.com/?submit.700987 (Submit #700987 | itsourcecode Student Information System V1.0 SQL Injection (Duplicate))
github.com/ltranquility/CVE/issues/15
itsourcecode.com/