CVE-2026-9573

A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of the file /admin/modules/student/index.php?view=view. Performing a manipulation of the argument studentId results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
Configurations

No configuration.

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad fue detectada en itsourcecode Student Transcript Processing System 1.0. Esto afecta una parte desconocida del archivo /admin/modules/student/index.php?view=view. Realizar una manipulación del argumento studentId resulta en inyección SQL. El ataque puede ser iniciado remotamente. El exploit es ahora público y puede ser usado.

27 May 2026, 18:16

Type Values Removed Values Added
References () https://github.com/nidieaaa/test/issues/12 - () https://github.com/nidieaaa/test/issues/12 -

26 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-26 20:16

Updated : 2026-07-23 11:10


NVD link : CVE-2026-9573

Mitre link : CVE-2026-9573

CVE.ORG link : CVE-2026-9573


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')