Description
A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Problem types
Product status
Timeline
| 2026-02-26: | Advisory disclosed |
| 2026-02-26: | VulDB entry created |
| 2026-02-26: | VulDB entry last update |
References
vuldb.com/?id.347984 (VDB-347984 | itsourcecode School Management System Setting index.php sql injection)
vuldb.com/?ctiid.347984 (VDB-347984 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.749364 (Submit #749364 | Ability School Management System V1.0 SQL Injection)
github.com/Ning-BJ/cve/issues/1
itsourcecode.com/