VYPR

School Management System

by Itsourcecode

CVEs (35)

  • CVE-2026-3261HigFeb 26, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has…

  • CVE-2026-2190HigFeb 8, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/user/controller.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been…

  • CVE-2026-2189HigFeb 8, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/report/index.php. The manipulation of the argument ay leads to sql injection. The attack can be initiated remotely. The exploit is publicly…

  • CVE-2026-2073HigFeb 7, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/user/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has…

  • CVE-2026-2018HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/settings/controller.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-2014HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /ramonsys/billing/index.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The…

  • CVE-2026-2013HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the file /ramonsys/soa/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available…

  • CVE-2026-2012HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /ramonsys/facultyloading/index.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit…

  • CVE-2026-2011HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /ramonsys/enrollment/controller.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit…

  • CVE-2026-1701HigJan 30, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in itsourcecode School Management System 1.0. This issue affects some unknown processing of the file /enrollment/index.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2026-1590HigJan 29, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/faculty/index.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly…

  • CVE-2026-1589HigJan 29, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/inquiry/index.php. This manipulation of the argument txtsearch causes sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2026-1545HigJan 28, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in itsourcecode School Management System 1.0. The affected element is an unknown function of the file /course/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has…

  • CVE-2026-1176HigJan 19, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in itsourcecode School Management System 1.0. Affected is an unknown function of the file /subject/index.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit…

  • CVE-2026-0544HigJan 1, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in itsourcecode School Management System 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2026-1551MedJan 29, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/course/controller.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been…

  • CVE-2024-31610Apr 25, 2024
    risk 0.00cvss epss 0.00

    File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1.0 allows attackers to run arbitrary code via upload of crafted file.

  • CVE-2022-34580Jul 28, 2022
    risk 0.00cvss epss 0.00

    Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the address parameter at ip/school/index.php.

  • CVE-2022-34594Jul 27, 2022
    risk 0.00cvss epss 0.00

    Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component ip/school/moudel/update_subject.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the…

  • CVE-2022-34586Jul 20, 2022
    risk 0.00cvss epss 0.01

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/student_grade_wise.php.

Page 1 of 2