SQL Injection Vulnerability in itsourcecode Online Student Enrollment System
CVE-2026-36233

Currently unrated

Key Information:

Vendor
CVE Published:
10 April 2026

What is CVE-2026-36233?

A SQL injection vulnerability exists in the assignInstructorSubjects.php file of the itsourcecode Online Student Enrollment System version 1.0. This flaw allows attackers to inject malicious SQL code through the 'subjcode' parameter, which is directly used in SQL queries without proper input validation or sanitization. This could potentially lead to unauthorized access to sensitive data or manipulation of the database.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.