Impact
A SQL injection flaw exists in the Parameter Handler component of itsourcecode Online Enrollment System 1.0, triggered by manipulating the deptid argument in /enrollment/index.php?view=edit&id=3. The flaw allows an attacker to inject arbitrary SQL code, which can lead to unauthorized data disclosure, modification, or deletion. The vulnerability is classified as CWE-89 (SQL Injection) and CWE-74 (Input Parameter Manipulation).
Affected Systems
The affected product is itsourcecode Online Enrollment System version 1.0, accessed via the enrollment/index.php interface. No other versions or variants are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 reflects moderate severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation. However, a public exploit has been released, and the vulnerability can be exploited remotely without authentication. Although the issue is not currently listed in CISA’s KEV catalog, its remote nature and public exploit availability render it a notable risk, especially for systems that store sensitive enrollment data.
OpenCVE Enrichment