CVE-2026-3149

A weakness has been identified in itsourcecode College Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/asign-single-student-subjects.php. Executing a manipulation of the argument course_code can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
References
Link Resource
https://github.com/Zhangchao404/cve/issues/1 Exploit Issue Tracking Mitigation Third Party Advisory
https://itsourcecode.com/ Product
https://vuldb.com/?ctiid.347657 Permissions Required VDB Entry
https://vuldb.com/?id.347657 Third Party Advisory VDB Entry
https://vuldb.com/?submit.758828 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:angeljudesuarez:college_management_system:1.0:*:*:*:*:*:*:*

History

25 Feb 2026, 17:53

Type Values Removed Values Added
First Time Angeljudesuarez college Management System
Angeljudesuarez
CPE cpe:2.3:a:angeljudesuarez:college_management_system:1.0:*:*:*:*:*:*:*
References () https://github.com/Zhangchao404/cve/issues/1 - () https://github.com/Zhangchao404/cve/issues/1 - Exploit, Issue Tracking, Mitigation, Third Party Advisory
References () https://itsourcecode.com/ - () https://itsourcecode.com/ - Product
References () https://vuldb.com/?ctiid.347657 - () https://vuldb.com/?ctiid.347657 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.347657 - () https://vuldb.com/?id.347657 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.758828 - () https://vuldb.com/?submit.758828 - Third Party Advisory, VDB Entry

25 Feb 2026, 14:15

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una debilidad en itsourcecode College Management System 1.0 que afecta a alguna funcionalidad desconocida del archivo /admin/asign-single-student-subjects.PHP. La manipulación del argumento course_code puede provocar una inyección SQL. El ataque puede ejecutarse de forma remota. El exploit se ha hecho público y podría usarse para ataques.

25 Feb 2026, 05:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 05:17

Updated : 2026-02-25 17:53


NVD link : CVE-2026-3149

Mitre link : CVE-2026-3149

CVE.ORG link : CVE-2026-3149


JSON object : View

Products Affected

angeljudesuarez

  • college_management_system
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')