Executive brief
A security vulnerability exists in the itsourcecode Online Student Enrollment System, a platform used for managing student registrations. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to steal sensitive student information, modify academic records, or disrupt school operations. This issue can be exploited remotely without requiring any login credentials.
Technical details
A SQL injection vulnerability exists in itsourcecode Online Student Enrollment System v1.0 within the 'scheduleSubList.php' component. The vulnerability is caused by the improper neutralization of the 'subjcode' parameter, which is directly concatenated into a SQL query string without sanitization or the use of prepared statements. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request to the vulnerable endpoint. Successful exploitation allows for full database compromise, including the ability to read, modify, or delete arbitrary data. No patches are currently documented in the advisory.
Affected products
- itsourcecode Online Student Enrollment System 1.0
Timeline
- 2026-04-10: disclosed
- 2026-04-10: advisory