Impact
A flaw in itsourcecode Online Enrollment System allows a remote attacker to inject arbitrary SQL through the USERID parameter in the /sms/user/index.php?view=edit&id=10 URL. By manipulating this input, the attacker can execute commands against the database, enabling read, modify, or delete operations on enrollment records. This vulnerability is a classic SQL injection (CWE-89) and may also involve improper handling of URL arguments (CWE-74). The result is a breach of confidentiality, integrity, and potentially availability if the database is corrupted.
Affected Systems
The affected product is itsourcecode Online Enrollment System version 1.0. The vulnerability resides in a potentially unknown function within the Parameter Handler component of that product. No other versions or platforms are specified.
Risk and Exploitability
The CVSS score of 6.9 marks the vulnerability as medium‑high severity. Although no EPSS score is reported and the flaw is not listed in the CISA KEV catalog, the exploit is publicly available and can be performed remotely. Consequently, the likelihood of real‑world exploitation is significant, and the risk to sensitive enrollment data is high.
OpenCVE Enrichment