SQL Injection Vulnerability in itsourcecode Online Admission System 1.0
CVE-2026-105183
Key Information:
- Vendor
Itsourcecode
- Status
- Vendor
- CVE Published:
- 5 October 2026
Badges
What is CVE-2026-105183?
A SQL injection vulnerability has been found in the itsourcecode Online Admission System 1.0, specifically affecting the /admin/confirm.php file. The vulnerability allows an attacker to manipulate the argument 'schedid', enabling unauthorized SQL commands to be executed remotely. This could potentially lead to data leakage or manipulation. Publicly available exploits for this vulnerability make it critical for users to secure their installations.
Affected Version(s)
Online Admission System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
