CVE-2026-3413

critical
Published 2026-03-02 · Modified 2026-04-29
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /admin_single_student.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cna@vuldb.com — https://github.com/JXBbozaihuang/vuln-research/issues/1

Application impact

VendorProductVersionsFixed
angeljudesuarezuniversity_management_system1.0

References

CWEs

CWE-74 CWE-89

Verify integrity in audit chain (admin only). AS-IS.