A vulnerability, which was classified as critical, was found in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /admin/student-fee.php. Such manipulation of the argument roll_no leads to sql injection.
This vulnerability is referenced as CVE-2026-3486. It is possible to launch the attack remotely. Furthermore, an exploit is available.