SQL Injection Vulnerability in itsourcecode Student Transcript Processing System 1.0
CVE-2026-9573
Key Information:
- Vendor
Itsourcecode
- Vendor
- CVE Published:
- 26 May 2026
Badges
What is CVE-2026-9573?
A significant SQL injection vulnerability has been discovered in the itsourcecode Student Transcript Processing System version 1.0. Located specifically in the /admin/modules/student/index.php?view=view file, the vulnerability allows remote attackers to manipulate the studentId argument, leading to unauthorized database access and potential data breaches. This exploit has been made public, increasing the urgency for affected users to address it promptly to protect sensitive information.
Affected Version(s)
Student Transcript Processing System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
