Junglewise Threat Intelligence

CVE-2026-5534: itsourcecode Online Enrollment System SQL injection in USERID parameter

CVE-2026-5534 · Severity: high · CVSS 7.3 · Published 2026-04-05

Vendors: Itsourcecode.

Executive brief

A vulnerability exists in the itsourcecode Online Enrollment System, a web application used for managing student registrations. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially exposing sensitive student or administrative information. This could lead to data theft, unauthorized modification of records, or disruption of the enrollment process.

Technical details

A SQL injection vulnerability exists in itsourcecode Online Enrollment System 1.0 within the Parameter Handler component. The flaw is located in the '/sms/user/index.php' file and is triggered by manipulating the 'USERID' argument during a 'view=edit' request. A remote, unauthenticated attacker can exploit this by sending specially crafted SQL queries to the server. Successful exploitation allows the attacker to read, modify, or delete data from the database. A public exploit (Proof of Concept) is reportedly available.

Affected products

  • itsourcecode Online Enrollment System 1.0

Timeline

  • 2026-04-05: disclosed
  • 2026-04-05: advisory

References