CVE-2026-5534: itsourcecode Online Enrollment System Parameter index.php sql injection
A vulnerability was identified in itsourcecode Online Enrollment System 1.0. This affects an unknown function of the file /sms/user/index.php?view=edit&id=10 of the component Parameter Handler. Such manipulation of the argument USERID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5534?
CVE-2026-5534 is classified as a high severity vulnerability due to the potential for SQL injection attacks.
How do I fix CVE-2026-5534?
To fix CVE-2026-5534, update itsourcecode Online Enrollment System to the latest version that contains a patch for this vulnerability.
What type of vulnerability is CVE-2026-5534?
CVE-2026-5534 is an SQL injection vulnerability that allows unauthorized access to the database.
Which component is affected by CVE-2026-5534?
CVE-2026-5534 affects the Parameter Handler component in the /sms/user/index.php file.
What versions are affected by CVE-2026-5534?
CVE-2026-5534 affects only version 1.0 of the itsourcecode Online Enrollment System.