Sceawere
Vulnerability Detail
CVE-2026-105253UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Online Admission System SQL Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 10h ago
- Vendor
- itsourcecode
- Product
- Online Admission System Project
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-05T09:17:11.753Z",
"pubdate": "2026-10-05T09:17:11.753Z",
"executiveSummary": "The Online Admission System Project 1.0 is susceptible to a remote SQL injection vulnerability residing within the /admin/login1.php script.\nThe vulnerability occurs due to improper neutralization of user-supplied data passed through the 'User' argument before being processed by the backend database.\nAn unauthenticated, remote attacker can exploit this flaw to manipulate backend SQL queries, potentially bypassing authentication mechanisms, accessing unauthorized administrative data, or compromising the integrity and confidentiality of the database.\nGiven that the exploit has been publicly disclosed, the risk to instances of this software is high. Attackers can leverage this vulnerability without needing prior system access, making it a critical threat to any exposed deployment of the Online Admission System 1.0.",
"technicalDetails": "The vulnerability is a classic SQL injection flaw located in the /admin/login1.php file of the Online Admission System Project 1.0. The root cause is the insecure handling of the 'User' input parameter, which is incorporated directly into a database query string without sufficient sanitization, parameterization, or the use of prepared statements.\nThe attack flow begins when an attacker sends a crafted HTTP request to the /admin/login1.php endpoint. By injecting malicious SQL syntax into the 'User' argument, the attacker alters the logic of the intended query. For example, if the backend code constructs a query like \"SELECT * FROM admins WHERE username = '$user'\", an attacker could provide a value such as \"admin' OR '1'='1\" to force the query to evaluate as true regardless of the actual credentials.\nThis manipulation allows an attacker to bypass the authentication gate, effectively logging in as an administrator without valid credentials. Beyond simple bypass, the vulnerability allows for 'UNION-based' or 'error-based' SQL injection techniques, enabling the attacker to extract sensitive information from other tables within the database schema, such as user credentials, personal student data, or system configuration parameters.\nSince the attack is initiated remotely via HTTP, there are no requirements for pre-existing authentication or specialized privileges. The vulnerable component is the login authentication logic within the PHP script. The lack of input validation and the absence of parameterized queries mean the database engine treats the attacker-supplied input as executable code rather than plain data. The post-exploitation impact includes full administrative compromise of the web application, potential database exfiltration, and the ability to escalate privileges within the environment by modifying user records or injecting new administrative accounts. As the exploit is publicly disclosed, automated scanners and threat actors can easily identify and weaponize this entry point."
}