Sceawere

Vulnerability Detail

CVE-2026-105184UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Online Admission System

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
15h ago
Vendor
itsourcecode
Product
Online Admission System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in itsourcecode Online Admission System 1.0. The impacted element is an unknown function of the file /admin/creteria.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T03:16:38.890Z",
  "pubdate": "2026-10-05T03:16:38.890Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified in the itsourcecode Online Admission System version 1.0. The vulnerability resides within the /admin/creteria.php file and is triggered through the manipulation of the ID argument.\nThis flaw allows remote, unauthenticated attackers to execute arbitrary SQL commands against the underlying database, potentially leading to unauthorized data access, modification, or deletion. The vulnerability poses a significant risk to the integrity and confidentiality of the application's database.\nBecause the exploit has been disclosed publicly, the risk of exploitation is elevated. Attackers can leverage this vulnerability to gain complete control over the database, bypass authentication mechanisms, or extract sensitive administrative and user data. Immediate remediation is necessary to prevent potential security breaches.",
  "technicalDetails": "The vulnerability is a classic SQL injection flaw stemming from improper neutralization of special elements used in an SQL command within the /admin/creteria.php script of the itsourcecode Online Admission System 1.0.\nThe root cause of this vulnerability is the application's failure to adequately sanitize or parameterize the 'ID' argument before incorporating it into a database query. When user-supplied input is passed directly into the SQL query string without validation or the use of prepared statements, the application becomes susceptible to malicious payload injection.\nAn attacker can exploit this by manipulating the 'ID' parameter in a crafted HTTP GET or POST request directed at /admin/creteria.php. By injecting SQL syntax (such as UNION operators, boolean-based flags, or time-based blind SQLi payloads), the attacker can alter the intended logic of the query executed by the database management system (DBMS).\nThe attack flow proceeds as follows: 1. The attacker identifies the vulnerable /admin/creteria.php file and the target parameter 'ID'. 2. The attacker submits a crafted HTTP request containing malicious SQL characters (e.g., ' or 1=1--). 3. The server-side script interprets the input as part of the query, effectively executing the attacker's SQL commands. 4. The DBMS processes the modified query, returning unintended data or performing unauthorized actions. 5. The application returns the results or error messages to the attacker, providing feedback for further exploitation.\nSuccessful exploitation of this vulnerability allows for post-exploitation impacts including full database enumeration, exfiltration of administrative credentials, access to student or system data, and in some database configurations, potential remote command execution on the host server if specific database functions or system-level permissions are accessible to the database user.\nThe vulnerability is accessible remotely over the network, and the lack of robust input validation mechanisms in the affected component makes it a high-severity entry point for attackers seeking to compromise the system's data integrity."
}
CVE-2026-105184: SQL Injection in Online Admission System (HIGH Severity, CVSS: 7.3) | Sceawere