Impact
The Online Admission System’s login1.php file accepts a User argument that, when manipulated, allows arbitrary SQL statements to be executed by the underlying database. This flaw exists because the input is not properly sanitized or bound to a parameterized query, resulting in a classic SQL injection vulnerability (CWE‑74 and CWE‑89). An attacker can supply specially crafted input to read, modify, or delete data from the database, potentially exposing sensitive personal information used within the admission process. If exploited, the adversary could gain elevated privileges or disrupt normal operation of the admission system.
Affected Systems
The vendor itsourcecode produces the Online Admission System, version 1.0. This version is vulnerable when the login1.php file processes user credentials without limiting or escaping the User input. No other versions are explicitly listed as affected, but the vulnerability description applies to all installations that have not applied a corrective update.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, and the exploit is publicly available, which means attackers can initiate the injection from a remote host. Although EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, the public proof‑of‑concept code and documented exploitation paths raise the likelihood of real‑world attacks. Because the flaw is reachable via a remote web interface, highly exposed servers with the default configuration are at the greatest risk. The potential impact ranges from data disclosure to full database compromise if no mitigation steps are taken.
OpenCVE Enrichment