Sceawere
Vulnerability Detail
CVE-2026-105183UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Online Admission System
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 15h ago
- Vendor
- itsourcecode
- Product
- Online Admission System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is an unknown function of the file /admin/confirm.php. This manipulation of the argument schedid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-05T03:16:38.717Z",
"pubdate": "2026-10-05T03:16:38.717Z",
"executiveSummary": "The itsourcecode Online Admission System version 1.0 contains a critical SQL injection vulnerability within the /admin/confirm.php file. This security flaw stems from the improper sanitization of user-supplied input provided through the 'schedid' parameter.\nSuccessful exploitation of this vulnerability allows an unauthenticated remote attacker to manipulate database queries, leading to unauthorized access, modification, or deletion of sensitive information stored within the backend database. Given that the exploit code is publicly available, the risk of exploitation is significantly elevated.\nThe vulnerability represents a direct threat to the integrity and confidentiality of the admission data. Attackers can leverage this flaw to execute arbitrary SQL commands, potentially gaining administrative-level access or compromising the underlying database management system. Organizations using this software are at high risk of data breaches and unauthorized system manipulation. Immediate remediation is required to sanitize all dynamic inputs processed by the application’s database layer.",
"technicalDetails": "The vulnerability is classified as a SQL injection flaw located in the /admin/confirm.php script of the itsourcecode Online Admission System 1.0. The root cause of this issue is the application's failure to properly validate, sanitize, or parameterize the 'schedid' HTTP GET or POST parameter before concatenating it into a database query string.\nThe attack flow begins when an attacker sends a crafted malicious request to the vulnerable endpoint /admin/confirm.php. By injecting SQL syntax characters—such as single quotes, comments, or logical operators—into the 'schedid' field, the attacker breaks out of the intended query structure. Because the application processes this input directly, the underlying database management system executes the attacker's injected SQL commands with the privileges assigned to the web application’s database user.\nThis vulnerability is reachable remotely over the network without requiring prior authentication, significantly widening the attack surface. An attacker can employ various techniques, including boolean-based, time-based, or error-based blind SQL injection, to systematically extract the database schema, administrative credentials, or personally identifiable information of applicants. Furthermore, if the database user possesses sufficient permissions, an attacker may be able to read or write local files on the server or execute operating system commands.\nThe exploit mechanism involves manipulating the 'schedid' parameter to bypass authentication checks or filter-based logic implemented in the application. For instance, by appending 'OR 1=1' to the parameter, the attacker can force the query to evaluate as true, potentially accessing restricted records or bypassing authorization checks intended to limit the scope of the confirmation process. The presence of public exploit code lowers the barrier to entry, enabling automated scanning and opportunistic exploitation by malicious actors. The lack of parameterized queries or prepared statements is the primary driver of this insecurity, as it prevents the separation of executable code from user-supplied data, allowing the database to interpret attacker-controlled input as legitimate commands."
}