Description
A security flaw has been discovered in itsourcecode Online Admission System Project 1.0. The impacted element is an unknown function of the file confirm.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Remote SQL Injection allowing data exposure
Action: Apply Fix
AI Analysis

Impact

A flaw in the confirm.php file of itsourcecode Online Admission System Project 1.0 enables an attacker to manipulate the ID argument and inject arbitrary SQL. The injection can be used to query, modify or delete data stored in the underlying database, potentially exposing sensitive user information or disrupting the admission workflow. The description states that the attack may be launched remotely and that a public exploit has been released.

Affected Systems

The vulnerability affects itsourcecode Online Admission System Project, version 1.0. Systems running this version with the confirm.php endpoint accessible to external parties are at risk. No patch or update version is listed in the provided data.

Risk and Exploitability

The CVSS score of 5.3 signals a moderate severity. The EPSS score is not available, but the ACK that a public exploit exists suggests a realistic exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, yet remote attackers can exploit it without authentication based on the description. The risk is amplified on publicly exposed instances where the confirm.php page is reachable.

Generated by OpenCVE AI on October 2, 2026 at 11:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Implement parameterized queries or prepared statements for the ID argument in confirm.php to prevent SQL injection.
  • Remove or restrict direct access to confirm.php via web server configuration, ensuring only trusted internal users can invoke it.
  • Apply any vendor‑issued patch or update to version 1.0 as soon as it is released. If none is available, establish a monitoring strategy that detects suspicious SQL activity and block offending IP addresses.

Generated by OpenCVE AI on October 2, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester online Admission System
Vendors & Products Sourcecodester
Sourcecodester online Admission System

Fri, 02 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in itsourcecode Online Admission System Project 1.0. The impacted element is an unknown function of the file confirm.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Title itsourcecode Online Admission System Project confirm.php sql injection
First Time appeared Itsourcecode
Itsourcecode online Admission System Project
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:online_admission_system_project:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode online Admission System Project
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Online Admission System Project
Sourcecodester Online Admission System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-02T10:30:16.407Z

Reserved: 2026-10-02T03:33:20.669Z

Link: CVE-2026-104606

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T11:17:26.037

Modified: 2026-10-02T13:18:55.613

Link: CVE-2026-104606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:14Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')