Itsourcecode · Itsourcecode School Management System · CVE-2026-0544
**Name of the Vulnerable Software and Affected Versions**
itsourcecode School Management System version 1.0
**Description**
A security flaw exists in itsourcecode School Management System 1.0. The issue affects an unknown part of the file `/student/index.php`. Manipulation of the `ID` argument can lead to SQL injection. The attack can be launched remotely. The exploit has been publicly released and may be used for attacks.
**Recommendations**
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the `/student/index.php` file to minimize the risk of exploitation.