A vulnerability, which was classified as critical, has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /admin_single_student.php. This manipulation of the argument ID causes sql injection.

This vulnerability is tracked as CVE-2026-3413. The attack is possible to be carried out remotely. Moreover, an exploit is present.