Junglewise Threat Intelligence

CVE-2026-36952: Sourcecodester Online Thesis Archiving System SQL injection in manage_curriculum.php

CVE-2026-36952 · Severity: low · CVSS 2.7 · Published 2026-04-13

Vendors: SourceCodester.

Executive brief

The Online Thesis Archiving System, a web application for managing academic research papers, contains a security flaw in its administrative interface. An authorized administrator can exploit this vulnerability to gain unauthorized access to the underlying database. This could lead to the exposure of sensitive academic records or internal system information.

Technical details

A SQL injection vulnerability exists in Sourcecodester Online Thesis Archiving System v1.0 within the '/otas/admin/curriculum/manage_curriculum.php' file. The 'id' GET parameter is improperly neutralized before being used in a database query, allowing for Union-based SQL injection. An attacker with administrative privileges can exploit this to leak sensitive information from the database, such as the database name or other table data. The vulnerability requires authentication as an administrator and can be triggered via a specially crafted URL.

Affected products

  • Sourcecodester Online Thesis Archiving System 1.0

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory

References