Impact
The vulnerability is a classic SQL injection located in the admin/confirm.php file of itsourcecode Online Admission System 1.0. By manipulating the schedid argument, an attacker can embed arbitrary SQL commands. This flaw allows the attacker to read, modify or delete data stored in the underlying database, potentially exposing sensitive student enrollment information or corrupting admission records. The injection can be performed remotely without authentication due to the lack of input validation in the affected function.
Affected Systems
Itsourcecode Online Admission System version 1.0 is impacted. No additional product variants or version ranges were specified.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS is not provided, and the vulnerability is not listed in CISA KEV, suggesting no known large‑scale exploitation yet. The attack vector is inferred to be remote, via a standard HTTP request to the admin endpoint employing the schedid parameter. Because the exploit is publicly available, any site running the affected software without safeguards could be at risk.
OpenCVE Enrichment