CVE-2026-105183: itsourcecode Online Admission System confirm.php sql injection
A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is an unknown function of the file /admin/confirm.php. This manipulation of the argument schedid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be initiated remotely and requires no privileges or user interaction. An attacker would need to reach the affected application's /admin/confirm.php endpoint and supply a manipulated schedid argument.
Is public exploit information available?
Yes. The exploit has been made publicly available, which increases the likelihood of attempted exploitation.
How can I determine whether my deployment is affected?
Confirm whether you run itsourcecode Online Admission System version 1.0 and whether the /admin/confirm.php endpoint is exposed. Review web and application logs for suspicious requests containing manipulated schedid parameter values.