Description
A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /newrecord.php. Executing manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
Problem types
Product status
Timeline
| 2025-12-08: | Advisory disclosed |
| 2025-12-08: | VulDB entry created |
| 2025-12-08: | VulDB entry last update |
Credits
divehu (VulDB User)
References
github.com/J0kkeR/cve/issues/2
vuldb.com/?id.334763 (VDB-334763 | itsourcecode Student Management System newrecord.php sql injection)
vuldb.com/?ctiid.334763 (VDB-334763 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.702487 (Submit #702487 | itsourcecode Student Management System V1.0 SQL Injection)
github.com/J0kkeR/cve/issues/2
itsourcecode.com/