CVE-2026-86268: itsourcecode School Management System User_Login.php sql injection
A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file UserLogin.php. The manipulation of the argument email results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be executed remotely and requires no privileges or user interaction according to the supplied vector. A public exploit is available, increasing the likelihood of opportunistic exploitation.
What input and endpoint should defenders prioritize when investigating?
Investigation should focus on requests to User_Login.php and the email argument, which is the identified SQL injection point. The affected function within that file is not specified.
Which deployments are known to be affected?
The provided data identifies itsourcecode School Management System 1.0 as affected. It does not state whether other versions or configurations are affected.