CVE-2026-105187: itsourcecode Online Admission System key.php sql injection
Published Oct 5, 2026
·Updated
A vulnerability has been found in itsourcecode Online Admission System 1.0. Affected is an unknown function of the file /admin/key.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
itsourcecode Online Admission System=1.0
Event History
Oct 5, 2026
CVE Published
via MITRE·03:45 AM
Data Sourced
via MITRE·03:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker with at least low-level privileges can exploit the SQL injection through the ID argument in /admin/key.php. User interaction is not required.
2
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used by attackers.
3
What is the affected product and version?
The reported affected product is itsourcecode Online Admission System version 1.0. The vulnerable functionality is associated with /admin/key.php.