Impact
A flaw in the confirm.php file of itsourcecode Online Admission System Project 1.0 enables an attacker to manipulate the ID argument and inject arbitrary SQL. The injection can be used to query, modify or delete data stored in the underlying database, potentially exposing sensitive user information or disrupting the admission workflow. The description states that the attack may be launched remotely and that a public exploit has been released.
Affected Systems
The vulnerability affects itsourcecode Online Admission System Project, version 1.0. Systems running this version with the confirm.php endpoint accessible to external parties are at risk. No patch or update version is listed in the provided data.
Risk and Exploitability
The CVSS score of 5.3 signals a moderate severity. The EPSS score is not available, but the ACK that a public exploit exists suggests a realistic exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, yet remote attackers can exploit it without authentication based on the description. The risk is amplified on publicly exposed instances where the confirm.php page is reachable.
OpenCVE Enrichment