A vulnerability marked as critical has been reported in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/teacher-salary.php. This manipulation of the argument teacher_id causes sql injection.

The identification of this vulnerability is CVE-2026-3152. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.