CVE-2026-3747: itsourcecode University Management System add_result.php sql injection
A vulnerability was identified in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of the file /addresult.php. Such manipulation of the argument subject leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3747?
CVE-2026-3747 is considered a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2026-3747?
To fix CVE-2026-3747, sanitize and validate input parameters in the /add_result.php file to prevent SQL injection.
What is affected by CVE-2026-3747?
CVE-2026-3747 affects the itsourcecode University Management System version 1.0 specifically through the /add_result.php functionality.
Can CVE-2026-3747 lead to data breaches?
Yes, CVE-2026-3747 could lead to data breaches if attackers exploit the SQL injection vulnerability to access sensitive information.
Are there any known exploits for CVE-2026-3747?
As of now, there are no publicly reported exploits for CVE-2026-3747, but it remains a significant risk that should be addressed promptly.