SQL Injection Vulnerability in code-projects Online Application System for Admission
CVE-2026-2172

6.9MEDIUM

Key Information:

Vendor
CVE Published:
8 February 2026

What is CVE-2026-2172?

A vulnerability exists in the Online Application System for Admission 1.0, specifically within the Login Endpoint functionality of the file enrollment/index.php. This security flaw allows for SQL injection attacks, which can be executed remotely, potentially leading to unauthorized access to sensitive data. Given that this exploit is publicly disclosed, it poses a significant risk if not addressed promptly.

Affected Version(s)

Online Application System for Admission 1.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

imcoming (VulDB User)
.