CVE-2026-105172: itsourcecode Online Admission System login1.php sql injection
A vulnerability was detected in itsourcecode Online Admission System 1.0. Affected by this issue is some unknown functionality of the file /login1.php. Performing a manipulation of the argument User results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerable login1.php endpoint can be attacked remotely without authentication or user interaction. Exploitation involves manipulating the User argument.
Is public exploit code available?
Yes. The available data states that an exploit is public and may be used, which increases the likelihood of opportunistic probing of exposed installations.
Which deployments should be prioritized for investigation?
Prioritize internet-accessible deployments of itsourcecode Online Admission System 1.0, particularly those where /login1.php is reachable. The affected functionality within that file is not further identified in the available data.