Description
A vulnerability was identified in itsourcecode Online Admission System 1.0. Impacted is an unknown function of the file /admin/schoolyear.php. Such manipulation of the argument sy leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Patch Now
AI Analysis

Impact

A flaw in the file /admin/schoolyear.php of itsourcecode Online Admission System allows manipulation of the 'sy' argument to inject SQL statements. The injection can be performed from a remote location and is publicly available, giving an attacker the ability to read, modify, or delete data stored in the system’s database. This directly compromises the confidentiality and integrity of admission records and could be abused to elevate privileges or disrupt service.

Affected Systems

The vulnerability affects version 1.0 of itsourcecode Online Admission System. No other versions or variants are listed in the available data.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. EPSS is not provided, but the exploit is publicly known and can be launched remotely, suggesting a realistic risk to unpatched systems. The system is not in the CISA KEV catalog. With CWE-74 and CWE-89 identifying string substitution and SQL injection weaknesses, an attacker can leverage unsanitised input to manipulate database queries.

Generated by OpenCVE AI on October 5, 2026 at 11:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for Online Admission System
  • Validate and sanitize the 'sy' parameter or use prepared statements to eliminate injection risk
  • Restrict access to /admin/schoolyear.php to authorized administrators only
  • Monitor database logs for anomalous query activity

Generated by OpenCVE AI on October 5, 2026 at 11:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in itsourcecode Online Admission System 1.0. Impacted is an unknown function of the file /admin/schoolyear.php. Such manipulation of the argument sy leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
Title itsourcecode Online Admission System schoolyear.php sql injection
First Time appeared Itsourcecode
Itsourcecode online Admission System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:online_admission_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode online Admission System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Online Admission System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T08:30:14.954Z

Reserved: 2026-10-04T17:56:44.900Z

Link: CVE-2026-105254

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:11.947

Modified: 2026-10-05T09:17:11.947

Link: CVE-2026-105254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:30:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')