CVE-2026-2013: itsourcecode Student Management System index.php sql injection
A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the file /ramonsys/soa/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2013?
CVE-2026-2013 has a medium severity due to its potential impact on the integrity of the database.
How do I fix CVE-2026-2013?
To fix CVE-2026-2013, validate and sanitize input parameters in the affected function to prevent SQL injection.
Which version of itsourcecode Student Management System is affected by CVE-2026-2013?
CVE-2026-2013 affects version 1.0 of the itsourcecode Student Management System.
What type of vulnerability is CVE-2026-2013?
CVE-2026-2013 is an SQL injection vulnerability that occurs through the manipulation of the argument ID.
How can I detect exploitation of CVE-2026-2013?
Exploitation of CVE-2026-2013 can be detected by monitoring for unusual database queries and error messages related to SQL.