CVE-2026-3410: itsourcecode Society Management System check_studid.php sql injection
A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checkstudid.php. Executing a manipulation of the argument studentid can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3410?
CVE-2026-3410 has been classified as a critical SQL injection vulnerability.
How does CVE-2026-3410 affect the itsourcecode Society Management System?
CVE-2026-3410 allows attackers to manipulate the student_id parameter in the check_studid.php file, leading to unauthorized database access.
How do I fix CVE-2026-3410?
To fix CVE-2026-3410, validate and sanitize all user inputs for the student_id parameter before processing.
What systems are vulnerable to CVE-2026-3410?
CVE-2026-3410 affects version 1.0 of the itsourcecode Society Management System.
What are the potential impacts of exploiting CVE-2026-3410?
Exploiting CVE-2026-3410 can lead to data leakage, database modification, or complete system compromise.