CVE-2026-4783
MEDIUMitsourcecode College Management System Parameter add-single-student-results.php sql injection
Title source: cnaDescription
A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown function of the file /admin/add-single-student-results.php of the component Parameter Handler. The manipulation of the argument course_code leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Scores
CVSS v3
6.3
EPSS
0.0003
EPSS Percentile
9.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-74
CWE-89
Status
published
Products (1)
itsourcecode/College Management System
1.0
Published
Mar 25, 2026
Tracked Since
Mar 25, 2026