Sceawere

Vulnerability Detail

CVE-2026-105181UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in itsourcecode Online Admission System

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
15h ago
Vendor
itsourcecode
Product
Online Admission System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in itsourcecode Online Admission System 1.0. This issue affects some unknown processing of the file register1.php. The manipulation of the argument fname leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-05T03:16:38.367Z",
  "pubdate": "2026-10-05T03:16:38.367Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified in the itsourcecode Online Admission System version 1.0. The vulnerability stems from improper neutralization of user-supplied input within the 'fname' parameter processed by the 'register1.php' file. This flaw allows remote, unauthenticated attackers to manipulate backend database queries, potentially leading to unauthorized data disclosure, modification, or complete database compromise. Given that the exploit code is publicly available, the risk of exploitation is significantly elevated. The vulnerability affects the integrity and confidentiality of the underlying database, as attackers can execute arbitrary SQL commands to bypass authentication, dump sensitive user data, or alter system configurations. Organizations utilizing this system are at high risk of data breaches and service disruption. Immediate remediation is required to sanitize inputs and prevent unauthorized interactions with the application's database layer.",
  "technicalDetails": "The vulnerability resides in the 'register1.php' script of the itsourcecode Online Admission System 1.0, specifically within the processing logic handling the 'fname' argument. The root cause of this vulnerability is a failure to implement proper input validation or parameterization when passing the 'fname' argument directly into a database query. By failing to escape or sanitize the input, the application permits an attacker to inject malicious SQL syntax into the database engine.\nThe attack flow initiates when an unauthenticated remote attacker sends a specially crafted HTTP request to 'register1.php'. By injecting SQL command characters (such as single quotes, semicolons, or comment indicators) into the 'fname' field, the attacker can break out of the intended query structure. This allows the attacker to append additional SQL commands to the original statement, effectively executing arbitrary queries with the privileges of the database user configured for the application.\nExploitation involves the following technical steps: First, the attacker identifies the input vector through the 'fname' parameter in a POST or GET request directed at 'register1.php'. Second, the attacker crafts a payload designed to manipulate the query logic, such as using UNION-based injection to retrieve data from other tables or error-based techniques to infer schema information. Third, the crafted request is sent to the server. The server-side script then concatenates the malicious input into the SQL statement and executes it against the backend database management system (e.g., MySQL). Finally, the backend database processes the injected malicious commands, returning either the results of the unauthorized query or modifying the state of the database according to the attacker's instructions.\nThe potential post-exploitation impact includes full unauthorized access to sensitive data stored within the admission system, including student records, administrator credentials, and application logs. Furthermore, an attacker could potentially gain administrative control over the application by modifying account data, dropping tables, or escalating privileges. Because this vulnerability is exposed over the network, it does not require prior authentication, making it a highly accessible vector for malicious actors."
}
CVE-2026-105181: SQL Injection in itsourcecode Online Admission System (MEDIUM Severity, CVSS: 6.3) | Sceawere