Sceawere

Vulnerability Detail

CVE-2026-105185UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Online Admission

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
14h ago
Vendor
itsourcecode
Product
Online Admission System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in itsourcecode Online Admission System 1.0. This affects an unknown function of the file /admin/examinee.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-10-05T04:17:01.990Z",
  "pubdate": "2026-10-05T04:17:01.990Z",
  "executiveSummary": "A critical SQL injection (SQLi) vulnerability exists within the itsourcecode Online Admission System 1.0. The vulnerability resides in the /admin/examinee.php file, where the ID argument is inadequately sanitized before being processed by the backend database.\nThis flaw allows remote, unauthenticated or low-privileged attackers to manipulate database queries, leading to unauthorized data exfiltration, modification, or potential administrative account compromise. Given that the exploit code is publicly available, the risk of active exploitation is significant.\nThe vulnerability represents a failure to implement secure input validation and parameterized queries. The impact includes full database compromise, unauthorized access to sensitive applicant and administrative information, and the potential for lateral movement within the hosting environment. Organizations utilizing this version of the Online Admission System are at high risk and should prioritize immediate remediation.",
  "technicalDetails": "The vulnerability is a classic SQL injection flaw located in the /admin/examinee.php component of itsourcecode Online Admission System 1.0. The root cause is the insecure handling of the 'ID' parameter, which is passed directly into a SQL query executed against the application's database backend without appropriate input sanitization or the use of prepared statements.\nThe attack flow begins when an attacker identifies the vulnerable endpoint, /admin/examinee.php. By injecting malicious SQL syntax into the 'ID' parameter, an attacker can alter the structure of the intended database query. For example, by supplying crafted input, an attacker can bypass authentication checks, perform UNION-based queries to exfiltrate data from other tables, or leverage blind SQL injection techniques to infer database structure and content incrementally.\nBecause the application fails to validate the data type and format of the 'ID' argument, the backend interpreter treats user-supplied data as executable code rather than literal input. This allows for the execution of arbitrary SQL commands with the privileges of the database service account.\nThe attack can be initiated remotely via standard HTTP GET or POST requests. Since the exploit for this vulnerability is currently public, attackers can easily automate the discovery and exploitation process. Post-exploitation, an attacker can gain full visibility into the system's database, including administrator credentials, examinee personal identifying information (PII), and internal configuration data. In certain server configurations, this may lead to further system compromise, such as reading or writing arbitrary files on the filesystem if database features like 'INTO OUTFILE' are enabled.\nThe technical failure stems from the lack of defensive programming practices. Specifically, the application lacks parameterized queries (prepared statements), which are the industry standard for preventing SQLi by separating SQL logic from data input. The reliance on unsafe concatenation of user input into raw SQL strings facilitates this vulnerability, requiring immediate architectural changes to the codebase to remediate the underlying lack of input protection."
}
CVE-2026-105185: SQL Injection in Online Admission (HIGH Severity, CVSS: 7.3) | Sceawere