Description
A vulnerability was detected in itsourcecode Online Admission System 1.0. Affected by this issue is some unknown functionality of the file /login1.php. Performing a manipulation of the argument User results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Immediate Patch
AI Analysis

Impact

The Online Admission System’s login1.php file accepts a User argument that, when manipulated, allows arbitrary SQL statements to be executed by the underlying database. This flaw exists because the input is not properly sanitized or bound to a parameterized query, resulting in a classic SQL injection vulnerability (CWE‑74 and CWE‑89). An attacker can supply specially crafted input to read, modify, or delete data from the database, potentially exposing sensitive personal information used within the admission process. If exploited, the adversary could gain elevated privileges or disrupt normal operation of the admission system.

Affected Systems

The vendor itsourcecode produces the Online Admission System, version 1.0. This version is vulnerable when the login1.php file processes user credentials without limiting or escaping the User input. No other versions are explicitly listed as affected, but the vulnerability description applies to all installations that have not applied a corrective update.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity, and the exploit is publicly available, which means attackers can initiate the injection from a remote host. Although EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, the public proof‑of‑concept code and documented exploitation paths raise the likelihood of real‑world attacks. Because the flaw is reachable via a remote web interface, highly exposed servers with the default configuration are at the greatest risk. The potential impact ranges from data disclosure to full database compromise if no mitigation steps are taken.

Generated by OpenCVE AI on October 5, 2026 at 02:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check the vendor’s website or contact itsourcecode for a patch or updated version that addresses the login1.php SQL injection flaw.
  • Implement server‑side input validation that rejects non‑alphanumeric characters or that uses strict input length limits for the User field, and replace vulnerable concatenated queries with prepared statements or stored procedures.
  • Deploy a web application firewall configured to block common SQL injection patterns on the login endpoint and monitor access logs for anomalous query attempts.

Generated by OpenCVE AI on October 5, 2026 at 02:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 01:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in itsourcecode Online Admission System 1.0. Affected by this issue is some unknown functionality of the file /login1.php. Performing a manipulation of the argument User results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
Title itsourcecode Online Admission System login1.php sql injection
First Time appeared Itsourcecode
Itsourcecode online Admission System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:online_admission_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode online Admission System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Online Admission System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T00:00:11.348Z

Reserved: 2026-10-04T08:16:48.692Z

Link: CVE-2026-105172

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T01:16:27.157

Modified: 2026-10-05T01:16:27.157

Link: CVE-2026-105172

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T02:30:08Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')