CVE-2026-105186: itsourcecode Online Admission System new.php sql injection
Published Oct 5, 2026
·Updated
A flaw has been found in itsourcecode Online Admission System 1.0. This impacts an unknown function of the file /new.php. Executing a manipulation of the argument schedid can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
Affected Software
1 affected component
itsourcecode Online Admission System=1.0
Event History
Oct 5, 2026
CVE Published
via MITRE·03:30 AM
Data Sourced
via MITRE·03:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack can be launched remotely, but the provided CVSS vector indicates low privileges are required. No user interaction is required.
2
Which component should be prioritized for review?
Review the /new.php endpoint, specifically handling of the schedid argument. The affected product version identified in the data is itsourcecode Online Admission System 1.0.
3
How mature is public exploitation?
An exploit has been published and may be used. The CVSS vector rates exploit maturity as proof-of-concept.