CVE-2026-2939
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to inject malicious scripts into the student management system, which can then be executed in the browsers of users visiting the affected page. The attacker can exploit this remotely, meaning they don't need physical access to the system, and the exploit details are publicly available, making it easier for them to launch an attack.
Technical Description
A vulnerability was found in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /add_student/ of the component Add Student Module. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used.
CVSS Vector Analysis
Vector String
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 22, 2026
about 1 month ago
Last Modified
Feb 23, 2026
about 1 month ago
Vendor
itsourcecode
Product
student management system
Related Vulnerabilities
An attacker can exploit a flaw in the Free Hotel Reservation System to manipulate a specific part of the website, allowing them to execute unauthorized SQL commands and potentially access or modify the database remotely. This vulnerability can be triggered simply by altering certain parameters in the URL, making it a serious risk for any system using this software.
This vulnerability allows an attacker to manipulate the database of the student management system by injecting harmful SQL code through the searchdata parameter, potentially exposing sensitive information or altering data. To exploit this, the attacker needs access to the search feature on the admin page.