Description
A vulnerability has been found in itsourcecode Online Admission System 1.0. Affected is an unknown function of the file /admin/key.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Remote SQL Injection
Action: Assess Impact
AI Analysis

Impact

A SQL injection flaw exists in the /admin/key.php page of the Online Admission System. An attacker can manipulate the ID argument to inject arbitrary SQL commands. Because the input is not properly sanitized, the back‑end database is exposed to tampering and data exfiltration. The flaw represents a classic SQL Injection weakness (CWE-89) arising from improper neutralization of special elements (CWE-74). Exploiting it could allow a remote attacker to read, modify, or delete admission records, thereby compromising confidentiality, integrity, and potentially availability of the application.

Affected Systems

The affected product is itsourcecode Online Admission System version 1.0. The vulnerable code resides in the admin key management component. Users running this configuration are at risk if the application is exposed to external traffic.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity risk. EPSS data is not available, so the exploitation probability cannot be quantified, but public disclosure and listed issues suggest the vulnerability is known and could be targeted. The vulnerability is not currently listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote, achievable through direct HTTP requests that supply a crafted ID parameter. An attacker would need network access to the web server but no additional privileges are required beyond submitting the request.

Generated by OpenCVE AI on October 5, 2026 at 05:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Online Admission System to the latest version once a vendor patch is released.
  • Implement input validation on the ID parameter in /admin/key.php, ensuring only numeric values are accepted.
  • Refactor the affected code to use parameterized SQL queries or stored procedures to eliminate direct query concatenation.
  • Enforce strict access controls so that only authorized administrative users can invoke the key management endpoint.
  • Configure web application firewalls to detect and block suspicious SQL injection patterns targeting the key.php URL.

Generated by OpenCVE AI on October 5, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 04:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in itsourcecode Online Admission System 1.0. Affected is an unknown function of the file /admin/key.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Title itsourcecode Online Admission System key.php sql injection
First Time appeared Itsourcecode
Itsourcecode online Admission System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:online_admission_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode online Admission System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Online Admission System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T03:45:07.580Z

Reserved: 2026-10-04T09:30:27.390Z

Link: CVE-2026-105187

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T04:17:07.887

Modified: 2026-10-05T04:17:07.887

Link: CVE-2026-105187

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T05:30:07Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')