CVE-2026-5334: itsourcecode Online Enrollment System Parameter index.php sql injection
Published Apr 2, 2026
·Updated
A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=edit&id=3 of the component Parameter Handler. This manipulation of the argument deptid causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
1 affected component
itsourcecode Online Enrollment System=1.0
Event History
Apr 2, 2026
CVE Published
via MITRE·01:45 PM
Data Sourced
via MITRE·01:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Apr 26, 58238
Event
via FIRST·10:00 AM