Description
A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is an unknown function of the file /admin/confirm.php. This manipulation of the argument schedid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote SQL Injection
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a classic SQL injection located in the admin/confirm.php file of itsourcecode Online Admission System 1.0. By manipulating the schedid argument, an attacker can embed arbitrary SQL commands. This flaw allows the attacker to read, modify or delete data stored in the underlying database, potentially exposing sensitive student enrollment information or corrupting admission records. The injection can be performed remotely without authentication due to the lack of input validation in the affected function.

Affected Systems

Itsourcecode Online Admission System version 1.0 is impacted. No additional product variants or version ranges were specified.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. EPSS is not provided, and the vulnerability is not listed in CISA KEV, suggesting no known large‑scale exploitation yet. The attack vector is inferred to be remote, via a standard HTTP request to the admin endpoint employing the schedid parameter. Because the exploit is publicly available, any site running the affected software without safeguards could be at risk.

Generated by OpenCVE AI on October 5, 2026 at 04:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched or newer version of itsourcecode Online Admission System 1.0 once released.
  • Implement strict input validation on the schedid parameter, using parameterized queries or prepared statements to eliminate direct SQL concatenation.
  • Restrict access to the /admin/confirm.php endpoint so only authenticated, authorized staff can reach it, and monitor access logs for suspicious activity.

Generated by OpenCVE AI on October 5, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 03:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is an unknown function of the file /admin/confirm.php. This manipulation of the argument schedid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Title itsourcecode Online Admission System confirm.php sql injection
First Time appeared Itsourcecode
Itsourcecode online Admission System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:online_admission_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode online Admission System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Online Admission System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T02:45:16.668Z

Reserved: 2026-10-04T09:30:13.484Z

Link: CVE-2026-105183

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T03:16:38.717

Modified: 2026-10-05T03:16:38.717

Link: CVE-2026-105183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T04:30:04Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')