Description
A vulnerability was detected in itsourcecode Online Admission System 1.0. This affects an unknown function of the file /admin/examinee.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote SQL Injection
Action: Immediate Patch
AI Analysis

Impact

A SQL injection flaw exists in the examinee.php component of the Online Admission System, allowing attackers to manipulate the ID argument to inject arbitrary database commands. This vulnerability can lead to disclosure or alteration of admission records, credential compromise, and potential escalation to full database compromise. The weakness is aligned with identifier CWE-89 and reflects improper handling of user input in database queries, as well as CWE-74 regarding incorrect use of SQL syntax.

Affected Systems

The flaw affects the itsourcecode Online Admission System, version 1.0, as identified by the vendor product name and a single CPE entry. Only this version is confirmed vulnerable; newer or patched releases are not listed in the current advisory.

Risk and Exploitability

The CVSS score is 6.9, indicating a moderate to high severity impact for exploitable errors. EPSS information is unavailable, so exploitation probability cannot be quantified at present. The vulnerability is not listed in CISA's KEV catalog, but the exploit is publicly known and remote. Attackers can send crafted requests over the network to trigger the injection; no special privileges are required beyond access to the exposed URL.

Generated by OpenCVE AI on October 5, 2026 at 04:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a version that includes the SQL injection fix.
  • Sanitize and validate the ID parameter before it is used in the query, ensuring it matches a strict numeric format or using prepared statements.
  • Deploy a web application firewall or utilize input sanitization libraries to block malformed queries touching the database layer.

Generated by OpenCVE AI on October 5, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in itsourcecode Online Admission System 1.0. This affects an unknown function of the file /admin/examinee.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
Title itsourcecode Online Admission System examinee.php sql injection
First Time appeared Itsourcecode
Itsourcecode online Admission System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:online_admission_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode online Admission System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Online Admission System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T03:15:11.104Z

Reserved: 2026-10-04T09:30:20.663Z

Link: CVE-2026-105185

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T04:17:01.990

Modified: 2026-10-05T04:17:01.990

Link: CVE-2026-105185

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T04:30:04Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')