PT-2026-6705 · Itsourcecode · Student Management System

·

CVE-2026-2012

·

Published

2026-02-06

·

Updated

2026-02-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions itsourcecode Student Management System version 1.0
Description A flaw exists in itsourcecode Student Management System 1.0. The issue involves the manipulation of the ID argument within an unknown function of the /ramonsys/facultyloading/index.php file, leading to a SQL injection condition. This allows for remote exploitation. The details of the exploit have been publicly disclosed.
Recommendations Apply any available updates or patches for itsourcecode Student Management System version 1.0. As a temporary workaround, restrict access to the /ramonsys/facultyloading/index.php file. Sanitize the ID parameter before using it in any database queries.

Exploit

Fix

SQL injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2012

Affected Products

Student Management System