Sceawere

Vulnerability Detail

CVE-2026-104606UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Online Admission System SQL Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
12h ago
Vendor
itsourcecode
Product
Online Admission System Project
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in itsourcecode Online Admission System Project 1.0. The impacted element is an unknown function of the file confirm.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-02T11:17:26.037Z",
  "pubdate": "2026-10-02T11:17:26.037Z",
  "executiveSummary": "A critical SQL injection vulnerability exists in the itsourcecode Online Admission System Project 1.0. The vulnerability resides within the confirm.php script, specifically impacting the handling of the ID argument.\nThis flaw allows a remote, unauthenticated attacker to manipulate database queries by injecting arbitrary SQL commands. Successful exploitation leads to unauthorized data access, potential modification or deletion of database contents, and compromise of the underlying database management system.\nThe vulnerability is currently exposed through publicly available exploit code, increasing the risk of active exploitation. Given that the system handles sensitive admission data, the potential for data exfiltration and integrity loss is high.\nNo authentication is required to perform this attack, as the injection point is reachable remotely without prior system access. This vulnerability poses a severe threat to the confidentiality, integrity, and availability of the Online Admission System and its associated backend database.",
  "technicalDetails": "The vulnerability is rooted in an improper neutralization of special elements used in an SQL command within the confirm.php file of the itsourcecode Online Admission System Project 1.0. Specifically, the application fails to adequately sanitize or parameterize the input provided via the ID argument before incorporating it into an SQL query string.\nThe attack flow commences when an attacker submits a crafted HTTP request targeting confirm.php, supplying a malicious SQL payload via the ID parameter. Because the application processes this input without sufficient validation or the use of prepared statements, the database engine interprets the attacker's input as executable SQL commands rather than literal data. This breach in the security boundary allows for the alteration of the query's logic, enabling unauthorized interactions with the database.\nBy manipulating the ID argument, an attacker can bypass standard application logic to execute unauthorized operations. This includes, but is not limited to, unauthorized data exfiltration (UNION-based SQLi), blind data inference (boolean-based or time-based SQLi), or potentially full administrative database takeover depending on the privileges assigned to the database user account used by the web application.\nSince the affected component, confirm.php, is accessible over the network without requiring prior authentication, the attack vector is categorized as remote. An attacker can use publicly available exploit scripts to automate the identification and exploitation process. Post-exploitation impact is significant; it allows for the unauthorized retrieval of sensitive user information, credentials, or admission records stored within the database. Furthermore, if the database configuration permits, an attacker might leverage advanced SQL injection techniques to write files to the web server's filesystem or execute administrative commands, leading to full system compromise. The absence of input filtering on the ID parameter effectively grants the attacker an interface to interact directly with the backend database management system without restrictions."
}
CVE-2026-104606: Online Admission System SQL Injection (MEDIUM Severity, CVSS: 6.3) | Sceawere