Critical Vulnerability Information Vulnerability Overview Type: SQL Injection Location: Student Result Manager application Cause: SQL statements were constructed using string concatenation with untrusted inputs (such as , , and ), and executed directly via . Severity Level: Critical CWE ID: CWE-89 (SQL Injection) CVSS v3.1 Score: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Affected Components File: Vulnerable Pattern: SQL statements built using string concatenation (e.g., ) and executed via a plain instead of parameterized queries or . Vulnerability Details The application constructs INSERT and UPDATE SQL statements by directly concatenating user-supplied values into SQL strings, then executes them using . When user input is embedded into SQL without proper parameterization or sanitization, attackers can inject SQL metacharacters and clauses to alter the intended query logic. Vulnerable Code Lines (Excerpts) Exploit Payload Examples ```sql '