CVE-2026-3740: itsourcecode University Management System admin_search_student.php sql injection
A weakness has been identified in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /adminsearchstudent.php. This manipulation of the argument adminsearchstudent causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3740?
The severity of CVE-2026-3740 is high due to its potential for SQL injection, which could lead to unauthorized access to the database.
How do I fix CVE-2026-3740?
To fix CVE-2026-3740, sanitize and validate all user inputs in the admin_search_student.php file to prevent SQL injection.
What is the impact of CVE-2026-3740?
The impact of CVE-2026-3740 includes potential data exposure or manipulation due to SQL injection within the University Management System.
Which versions of itsourcecode University Management System are affected by CVE-2026-3740?
CVE-2026-3740 affects version 1.0 of the itsourcecode University Management System.
Is CVE-2026-3740 a remote code execution vulnerability?
No, CVE-2026-3740 is not a remote code execution vulnerability; it specifically pertains to SQL injection.