Itsourcecode · School Management System · CVE-2026-2073
**Name of the Vulnerable Software and Affected Versions**
itsourcecode School Management System version 1.0
**Description**
A flaw exists in itsourcecode School Management System 1.0 that allows for SQL injection. This occurs through manipulation of the `ID` argument within the file '/ramonsys/user/index.php'. The attack can be carried out remotely. The exploit for this issue has been publicly disclosed.
**Recommendations**
Apply a fix to the vulnerable file '/ramonsys/user/index.php' to prevent manipulation of the `ID` argument.