SQL Injection Vulnerability in itsourcecode Online Student Enrollment System
CVE-2026-36233
Currently unrated
What is CVE-2026-36233?
A SQL injection vulnerability exists in the assignInstructorSubjects.php file of the itsourcecode Online Student Enrollment System version 1.0. This flaw allows attackers to inject malicious SQL code through the 'subjcode' parameter, which is directly used in SQL queries without proper input validation or sanitization. This could potentially lead to unauthorized access to sensitive data or manipulation of the database.
