CVE-2026-105184: itsourcecode Online Admission System creteria.php sql injection
A security vulnerability has been detected in itsourcecode Online Admission System 1.0. The impacted element is an unknown function of the file /admin/creteria.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be prioritized for assessment?
Deployments of itsourcecode Online Admission System 1.0 should be assessed, particularly where the affected application is reachable remotely. The available information does not state whether any configuration changes are required for exposure.
Does exploitation require authentication or user interaction?
The supplied vector indicates that exploitation requires neither privileges nor user interaction and can be launched remotely. The vulnerable input is the ID argument handled by /admin/creteria.php.
How urgent is mitigation?
The vulnerability is rated high severity with a 7.3 score, and a public exploit has been disclosed. Prioritize reducing remote access to the affected application while a vendor-supported remediation is identified.