CVE-2026-9573: itsourcecode Student Transcript Processing System index.php sql injection
A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of the file /admin/modules/student/index.php?view=view. Performing a manipulation of the argument studentId results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
itsourcecode Student Transcript Processing System 1.0from your environment.If the application is not required, uninstall/remove the itsourcecode Student Transcript Processing System 1.0 from any systems hosting it to eliminate exposure of the vulnerable endpoint.
- Compensating control
Restrict external access to the vulnerable endpoint (/admin/modules/student/index.php?view=view) and the /admin area (for example with firewall/ACL, VPN, or network segmentation). Deploy WAF/IPS rules to block SQL injection attempts targeting the studentId parameter until a vendor-provided patch or update is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9573?
CVE-2026-9573 has a high severity rating of 7.3.
How do I fix CVE-2026-9573?
To fix CVE-2026-9573, validate and sanitize user inputs to prevent SQL injection.
What type of vulnerability is CVE-2026-9573?
CVE-2026-9573 is classified as an SQL Injection vulnerability.
Can CVE-2026-9573 be exploited remotely?
Yes, CVE-2026-9573 can be exploited remotely.
What part of the system is affected by CVE-2026-9573?
CVE-2026-9573 affects the file /admin/modules/student/index.php in the itsourcecode Student Transcript Processing System.