Sceawere
Vulnerability Detail
CVE-2026-105185UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Online Admission
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 14h ago
- Vendor
- itsourcecode
- Product
- Online Admission System
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in itsourcecode Online Admission System 1.0. This affects an unknown function of the file /admin/examinee.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-05T04:17:01.990Z",
"pubdate": "2026-10-05T04:17:01.990Z",
"executiveSummary": "A critical SQL injection (SQLi) vulnerability exists within the itsourcecode Online Admission System 1.0. The vulnerability resides in the /admin/examinee.php file, where the ID argument is inadequately sanitized before being processed by the backend database.\nThis flaw allows remote, unauthenticated or low-privileged attackers to manipulate database queries, leading to unauthorized data exfiltration, modification, or potential administrative account compromise. Given that the exploit code is publicly available, the risk of active exploitation is significant.\nThe vulnerability represents a failure to implement secure input validation and parameterized queries. The impact includes full database compromise, unauthorized access to sensitive applicant and administrative information, and the potential for lateral movement within the hosting environment. Organizations utilizing this version of the Online Admission System are at high risk and should prioritize immediate remediation.",
"technicalDetails": "The vulnerability is a classic SQL injection flaw located in the /admin/examinee.php component of itsourcecode Online Admission System 1.0. The root cause is the insecure handling of the 'ID' parameter, which is passed directly into a SQL query executed against the application's database backend without appropriate input sanitization or the use of prepared statements.\nThe attack flow begins when an attacker identifies the vulnerable endpoint, /admin/examinee.php. By injecting malicious SQL syntax into the 'ID' parameter, an attacker can alter the structure of the intended database query. For example, by supplying crafted input, an attacker can bypass authentication checks, perform UNION-based queries to exfiltrate data from other tables, or leverage blind SQL injection techniques to infer database structure and content incrementally.\nBecause the application fails to validate the data type and format of the 'ID' argument, the backend interpreter treats user-supplied data as executable code rather than literal input. This allows for the execution of arbitrary SQL commands with the privileges of the database service account.\nThe attack can be initiated remotely via standard HTTP GET or POST requests. Since the exploit for this vulnerability is currently public, attackers can easily automate the discovery and exploitation process. Post-exploitation, an attacker can gain full visibility into the system's database, including administrator credentials, examinee personal identifying information (PII), and internal configuration data. In certain server configurations, this may lead to further system compromise, such as reading or writing arbitrary files on the filesystem if database features like 'INTO OUTFILE' are enabled.\nThe technical failure stems from the lack of defensive programming practices. Specifically, the application lacks parameterized queries (prepared statements), which are the industry standard for preventing SQLi by separating SQL logic from data input. The reliance on unsafe concatenation of user input into raw SQL strings facilitates this vulnerability, requiring immediate architectural changes to the codebase to remediate the underlying lack of input protection."
}