Junglewise Threat Intelligence

CVE-2026-36233: itsourcecode Online Student Enrollment System SQL injection in assignInstructorSubjects.php

CVE-2026-36233 · Severity: critical · CVSS 9.8 · Published 2026-04-10

Technologies: Itsourcecode Online Student Enrollment System. Vendors: Itsourcecode.

Executive brief

A security vulnerability exists in the itsourcecode Online Student Enrollment System, a platform used for managing student registrations. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to steal sensitive student information or modify academic records. This could lead to significant data breaches and loss of integrity for the educational institution's records.

Technical details

A SQL injection vulnerability exists in itsourcecode Online Student Enrollment System v1.0 within the 'assignInstructorSubjects.php' component. The vulnerability is caused by the improper neutralization of special elements in the 'subjcode' parameter, which is used directly in SQL queries without adequate validation or sanitization. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests to the vulnerable endpoint. Successful exploitation allows the attacker to perform unauthorized CRUD operations on the database, potentially leading to full data exfiltration or administrative bypass. No official patch has been identified in the advisory.

Affected products

  • itsourcecode Online Student Enrollment System 1.0

Timeline

  • 2026-04-10: disclosed
  • 2026-04-10: advisory

References

Related threats