Impact
A SQL injection flaw exists in the /admin/key.php page of the Online Admission System. An attacker can manipulate the ID argument to inject arbitrary SQL commands. Because the input is not properly sanitized, the back‑end database is exposed to tampering and data exfiltration. The flaw represents a classic SQL Injection weakness (CWE-89) arising from improper neutralization of special elements (CWE-74). Exploiting it could allow a remote attacker to read, modify, or delete admission records, thereby compromising confidentiality, integrity, and potentially availability of the application.
Affected Systems
The affected product is itsourcecode Online Admission System version 1.0. The vulnerable code resides in the admin key management component. Users running this configuration are at risk if the application is exposed to external traffic.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity risk. EPSS data is not available, so the exploitation probability cannot be quantified, but public disclosure and listed issues suggest the vulnerability is known and could be targeted. The vulnerability is not currently listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote, achievable through direct HTTP requests that supply a crafted ID parameter. An attacker would need network access to the web server but no additional privileges are required beyond submitting the request.
OpenCVE Enrichment