PT-2026-36292 · Sourcecodester · Advanced School Management System

Sqlmap961

·

Published

2026-05-01

·

Updated

2026-05-01

·

CVE-2026-7545

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SourceCodester Advanced School Management System version 1.0
Description A SQL injection flaw exists in the 'checkEmail' endpoint within the commonController.php file. This issue allows remote attackers to manipulate database queries through an unknown function, potentially leading to unauthorized data access or modification.
Recommendations Restrict access to the 'checkEmail' endpoint in the commonController.php file as a temporary mitigation measure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-7545

Affected Products

Advanced School Management System