Sceawere

Vulnerability Detail

CVE-2026-105186UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in itsourcecode Online Admission System

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
14h ago
Vendor
itsourcecode
Product
Online Admission System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in itsourcecode Online Admission System 1.0. This impacts an unknown function of the file /new.php. Executing a manipulation of the argument schedid can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-05T04:17:07.673Z",
  "pubdate": "2026-10-05T04:17:07.673Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified in itsourcecode Online Admission System 1.0. The vulnerability resides within the '/new.php' file, specifically due to improper neutralization of input provided through the 'schedid' parameter. This flaw allows a remote, unauthenticated attacker to manipulate database queries, leading to unauthorized data access, modification, or potential full database compromise. Given that an exploit is publicly available, the risk of exploitation is high. Successful exploitation requires no specialized privileges, allowing attackers to leverage the vulnerability remotely to interact directly with the backend database, potentially leading to a complete compromise of the application's data integrity and confidentiality.",
  "technicalDetails": "The vulnerability is a classic SQL injection flaw located in the '/new.php' file of the itsourcecode Online Admission System version 1.0. The root cause is the failure of the application to properly sanitize or parameterize the 'schedid' user-supplied input before incorporating it into a database query.\nWhen a user sends a request to '/new.php', the application processes the 'schedid' argument, likely using it in an 'SELECT', 'UPDATE', or 'DELETE' SQL statement. Because the input is not validated, an attacker can append malicious SQL syntax to the 'schedid' parameter. This allows the attacker to break out of the intended query structure, inject their own commands, and execute arbitrary SQL queries against the underlying database management system.\nThe attack flow proceeds as follows: An attacker sends a crafted HTTP GET or POST request to the '/new.php' endpoint. Within this request, the 'schedid' parameter is modified to contain SQL special characters, such as single quotes ('), semicolons (;), or comment sequences (-- or #). For example, injecting \"1' OR '1'='1\" might alter the query logic to bypass authentication or extract data intended to be restricted. Since the backend executes these statements with the permissions of the database user configured for the application, the attacker may be able to read sensitive tables, exfiltrate user credentials, or modify administrative settings.\nThis vulnerability is remotely exploitable and does not require the attacker to possess prior authentication or elevated privileges. Because the exploit is already public, the barrier to entry for attackers is significantly lowered. The post-exploitation impact includes complete loss of confidentiality and integrity of the data managed by the system, as well as the potential for further system compromise depending on the database configuration and underlying permissions."
}
CVE-2026-105186: SQL Injection in itsourcecode Online Admission System (MEDIUM Severity, CVSS: 6.3) | Sceawere