PT-2026-25745 · Itsourcecode · College Management System
2924909538
·
Publicado
2026-03-16
·
Atualizado
2026-03-16
·
CVE-2026-4241
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
itsourcecode College Management System version 1.0
Description
A flaw exists in itsourcecode College Management System version 1.0 that allows for remote SQL injection. The issue is located in the file
/admin/time-table.php within an unknown function. Manipulation of the course code parameter can trigger the injection. The exploit is publicly available.Recommendations
Apply a fix to the vulnerable file
/admin/time-table.php to address the SQL injection issue related to the course code parameter.Exploit
Correção
SQL injection
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
College Management System