Advanced School Management System Project maintains a narrowly scoped educational administration platform whose vulnerabilities concentrate in web-application input handling and file-upload controls. The durable exposure pattern reflects common web-tier weakness classes including SQL injection, cross-site scripting, and unrestricted file uploads that are characteristic of school information systems and their need to process and validate user-supplied data across multiple roles. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Advanced School Management System Project over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34588HIGH itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/timetable_insert_form.php. | Jul 20, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-34586HIGH itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via the grade parameter at /school/view/student_grade_wise.php. | Jul 20, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-32372HIGH itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject.php?id=. | Jun 15, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-32371HIGH itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_teacher.php?id=. | Jun 15, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-32370HIGH itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_classroom.php?id=. | Jun 15, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-32374HIGH itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject_routing.php?id=. | Jun 15, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-32373HIGH itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_exam.php?id=. | Jun 15, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-32368HIGH itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_grade.php?id=. | Jun 15, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-32433HIGH itsourcecode Advanced School Management System v1.0 is vulnerable to Arbitrary code execution via ip/school/view/all_teacher.php. | Jun 15, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-32381HIGH itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_admin_profile.php?my_index=. | Jun 15, 2022 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Advanced School Management System Project.
Media articles that mention a CVE ID that affects a product developed by Advanced School Management System Project — matched by CVE ID, not by vendor name.