CVE-2026-105185: itsourcecode Online Admission System examinee.php sql injection
A vulnerability was detected in itsourcecode Online Admission System 1.0. This affects an unknown function of the file /admin/examinee.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of itsourcecode Online Admission System 1.0 with the affected /admin/examinee.php endpoint reachable over the network are exposed. The vulnerable parameter is ID.
What does an attacker need to exploit it?
The attack can be initiated remotely by manipulating the ID argument. No privileges or user interaction are indicated by the supplied vector.
How likely is exploitation?
A public exploit is available, and the issue is rated high severity with a 7.3 score. This increases the practical risk for reachable affected installations.