Junglewise Threat Intelligence

CVE-2026-9575: itsourcecode Student Transcript Processing System SQL injection in index.php

CVE-2026-9575 · Severity: high · CVSS 7.3 · Published 2026-05-26

Technologies: Itsourcecode Student Transcript Processing System. Vendors: Itsourcecode.

Executive brief

A security vulnerability exists in the itsourcecode Student Transcript Processing System, a software package used for managing academic records. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to view, modify, or delete sensitive student information. This could lead to data breaches, unauthorized grade changes, or disruption of academic operations.

Technical details

A SQL injection vulnerability exists in itsourcecode Student Transcript Processing System 1.0 within the '/admin/modules/class/index.php' file. The application fails to properly validate or sanitize the 'id' parameter before using it in a database query. A remote, unauthenticated attacker can exploit this by sending specially crafted GET requests containing malicious SQL commands. Successful exploitation allows for unauthorized database access, including the ability to perform time-based blind or UNION-based queries to extract sensitive data or manipulate database records. No authentication or user interaction is required to trigger the vulnerability.

Affected products

  • itsourcecode Student Transcript Processing System 1.0

Timeline

  • 2026-05-01: disclosed: Vulnerability details and PoC shared on GitHub issue tracker.
  • 2026-05-26: advisory: CVE published and VulDB entry created.

References

Related threats