PT-2026-6705 · Itsourcecode · Student Management System

Tianrenu

·

Published

2026-02-06

·

Updated

2026-02-11

·

CVE-2026-2012

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions itsourcecode Student Management System version 1.0
Description A flaw exists in itsourcecode Student Management System 1.0. The issue involves the manipulation of the ID argument within an unknown function of the /ramonsys/facultyloading/index.php file, leading to a SQL injection condition. This allows for remote exploitation. The details of the exploit have been publicly disclosed.
Recommendations Apply any available updates or patches for itsourcecode Student Management System version 1.0. As a temporary workaround, restrict access to the /ramonsys/facultyloading/index.php file. Sanitize the ID parameter before using it in any database queries.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-2012

Affected Products

Student Management System