CVE-2026-3261Disclosure(itsourcecode / school_management_system)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • school_management_system

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-02-27); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
school_management_system

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-27: 3Mentions · 2026-03-03: 1Technical Details · 2026-02-27: 2Technical Details · 2026-03-03: 102-2703-03
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-273
Disclosure2General1
2026-03-031
Disclosure1
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3261 (CVSS:6.9, HIGH) is Analyzed. A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settin..https://nvd.nist.gov/vuln/detail/CVE-2026-3261 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-3261, noting a high‑severity flaw in School Management System 1.0, but provides no evidence of exploitation or mitigation.

    0000029
    173 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3261 A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. T… https://www.cve.org/CVERecord?id=CVE-2026-3261 ----- Traducción: Se ha encontrado … http://infoflow.cloud`

    Post summary

    A newly disclosed CVE (CVE-2026-3261) affects the School Management System 1.0, impacting an unknown function within /settings/index.php of the Setting Handler component.

    0000032
    55 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3261 A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. T… https://www.cve.org/CVERecord?id=CVE-2026-3261

    Post summary

    The statement reports a flaw in School Management System 1.0 affecting an unknown function in /settings/index.php, but offers no further details on exploitation, patches, or severity.

    00000211
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3261 SQL Injection in itsourcecode School Management System 1.0 via Settings Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3261

    Post summary

    A SQL injection vulnerability (CVE-2026-3261) affecting School Management System 1.0 via the Settings Handler has been disclosed, with details posted on vulmon.com.

    0000030
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appitsourcecodeschool_management_system1.0--

Explore more