CVE-2026-105253: itsourcecode Online Admission System Project login1.php sql injection
A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be initiated remotely and requires neither prior privileges nor user interaction. A publicly disclosed exploit exists and may be used.
Which systems should be treated as potentially affected?
Deployments of itsourcecode Online Admission System Project 1.0 should be reviewed, particularly where the /admin/login1.php endpoint is reachable. The affected processing is otherwise described as unknown.
What is the expected impact if exploitation succeeds?
The supplied severity vector rates the issue High at 7.3 and indicates low impacts to confidentiality, integrity, and availability.