CVE-2026-2011: itsourcecode Student Management System controller.php sql injection
A vulnerability was found in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /ramonsys/enrollment/controller.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2011?
CVE-2026-2011 has been classified as a critical vulnerability due to its potential for SQL injection.
How do I fix CVE-2026-2011?
To fix CVE-2026-2011, you should sanitize and validate all user inputs in the controller.php file.
What systems are affected by CVE-2026-2011?
CVE-2026-2011 affects version 1.0 of the itsourcecode Student Management System.
What type of attack does CVE-2026-2011 facilitate?
CVE-2026-2011 facilitates SQL injection attacks through manipulating the argument ID.
Is CVE-2026-2011 easy to exploit?
Yes, CVE-2026-2011 can be easily exploited by attackers who can interact with the affected application.