Description
A vulnerability was detected in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_student_query.php. The manipulation of the argument student_id results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2026-01-29: | Advisory disclosed |
| 2026-01-29: | VulDB entry created |
| 2026-01-29: | VulDB entry last update |
Credits
Shixu Wang (VulDB User)
References
vuldb.com/?id.343357 (VDB-343357 | itsourcecode Society Management System edit_student_query.php sql injection)
vuldb.com/?ctiid.343357 (VDB-343357 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.740692 (Submit #740692 | itsourcecode Society Management System V1.0 SQL Injection)
github.com/yyzq-wsx/for_cve/issues/1
itsourcecode.com/