CVE-2026-0544: itsourcecode School Management System index.php sql injection
A security flaw has been discovered in itsourcecode School Management System 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0544?
CVE-2026-0544 is classified as a severe vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2026-0544?
To fix CVE-2026-0544, you should update the itsourcecode School Management System to the latest version that addresses this SQL injection vulnerability.
What types of attacks can exploit CVE-2026-0544?
CVE-2026-0544 can be exploited through remote SQL injection attacks that manipulate the ID argument in the /student/index.php file.
Who is affected by CVE-2026-0544?
Users of itsourcecode School Management System version 1.0 are affected by CVE-2026-0544.
Is CVE-2026-0544 easy to exploit?
Yes, CVE-2026-0544 is considered easy to exploit as the vulnerability allows for remote attacks using SQL injection.