CVE-2026-1589
HIGHAngeljudesuarez School Management System - Injection
Title source: ruleDescription
A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/inquiry/index.php. This manipulation of the argument txtsearch causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
References (5)
Scores
CVSS v3
7.3
EPSS
0.0004
EPSS Percentile
11.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-74
CWE-89
Status
published
Affected Products (1)
angeljudesuarez/school_management_system
Timeline
Published
Jan 29, 2026
Tracked Since
Feb 18, 2026