CVE-2026-2018: itsourcecode School Management System controller.php sql injection
A flaw has been found in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/settings/controller.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2018?
CVE-2026-2018 has a high severity rating due to the potential for SQL injection exploitation within itsourcecode School Management System.
How do I fix CVE-2026-2018?
To fix CVE-2026-2018, validate and sanitize all input parameters in the /ramonsys/settings/controller.php file to prevent SQL injection.
What versions are affected by CVE-2026-2018?
CVE-2026-2018 affects itsourcecode School Management System version 1.0.
Can CVE-2026-2018 be exploited remotely?
Yes, CVE-2026-2018 can be exploited remotely if an attacker can manipulate the argument ID in the affected controller.php file.
What are the potential impacts of CVE-2026-2018?
The potential impacts of CVE-2026-2018 include unauthorized data access and manipulation due to SQL injection vulnerabilities.