Vulnerabilidad · Publicado 13/09/2026
Se identificó una vulnerabilidad de inyección SQL en SourceCodester School Registration and Fee System 1.0 en el archivo /bilal/normal/pay_report.php, permitiendo manipulación del parámetro 'period' para ejecutar comandos SQL arbitrarios. El exploit es público y explotable remotamente, afectando directamente instituciones educativas en México y LATAM que utilizan este sistema para gestión de matrículas y cobros. Con CVSS 7.3, requiere acción inmediata en entornos de producción.
A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Score: 7.3/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-74, CWE-89
Publicado en NIST NVD.