Impact
A SQL injection flaw exists in the examinee.php component of the Online Admission System, allowing attackers to manipulate the ID argument to inject arbitrary database commands. This vulnerability can lead to disclosure or alteration of admission records, credential compromise, and potential escalation to full database compromise. The weakness is aligned with identifier CWE-89 and reflects improper handling of user input in database queries, as well as CWE-74 regarding incorrect use of SQL syntax.
Affected Systems
The flaw affects the itsourcecode Online Admission System, version 1.0, as identified by the vendor product name and a single CPE entry. Only this version is confirmed vulnerable; newer or patched releases are not listed in the current advisory.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate to high severity impact for exploitable errors. EPSS information is unavailable, so exploitation probability cannot be quantified at present. The vulnerability is not listed in CISA's KEV catalog, but the exploit is publicly known and remote. Attackers can send crafted requests over the network to trigger the injection; no special privileges are required beyond access to the exposed URL.
OpenCVE Enrichment