SQL Injection Vulnerability in itsourcecode Online Admission System
CVE-2026-105172 is a remote SQL injection vulnerability in itsourcecode Online Admission System 1.0, reachable via the User parameter in /login1.php, for which public exploit code is available.
CVE search metadata
CVE search record: CVE-2026-105172. Severity: high. CVSS: 7.3. KEV: no. Product: Online Admission System (1.0). Brief: SQL Injection Vulnerability in itsourcecode Online Admission System. Brief link: https://feed.craftedsignal.io/briefs/2026-10-online-admission-sqli/
What's new
- 1. added detection rule: Detects CVE-2026-105183 Exploitation - Remote SQL Injection Oct 5, 03:43 via nvd
CVE-2026-105172 is a high-severity SQL injection vulnerability affecting version 1.0 of the itsourcecode Online Admission System. The flaw resides within the /login1.php script, specifically in the processing of the 'User' argument. An unauthenticated remote attacker can supply crafted SQL payloads within this parameter to manipulate backend database queries. This vulnerability allows for unauthorized data extraction, modification, or bypass of authentication mechanisms. Public exploit code for this vulnerability is currently available, increasing the risk of active exploitation by opportunistic actors. Organizations using this software should restrict access to the application or apply compensating controls at the web application firewall level until a patch is available.
Attack Chain
- Attacker performs reconnaissance to identify systems running itsourcecode Online Admission System 1.0.
- Attacker crafts an HTTP POST or GET request targeting the /login1.php endpoint.
- Attacker injects malicious SQL syntax into the 'User' parameter.
- The vulnerable application passes the unsanitized 'User' input directly to the SQL query.
- The backend database executes the injected command with application-level privileges.
- Attacker exfiltrates sensitive database content or bypasses login controls to gain unauthorized access.
Impact
Successful exploitation of this vulnerability can lead to complete compromise of the application database, including the theft of administrative credentials and student personal data. Given the availability of public exploits, the potential for automated exploitation is high, and organizations deploying this system are at significant risk of data exfiltration and integrity loss.
Recommendation
- Deploy a web application firewall (WAF) rule to block requests containing SQL injection patterns directed at /login1.php.
- Audit web server logs for HTTP requests to /login1.php where the 'User' parameter contains SQL keywords like 'UNION', 'SELECT', or '--'.
- Restrict external network access to the Online Admission System interface until the vendor provides a remediation or patch.
Immediate actions
Implement WAF blocking rules for /login1.php SQLi patterns
Threat Hunt
Search web logs for 200 or 500 status codes on /login1.php with signs of SQLi in the query string
Data: Web server access logs
Mitigations
Restrict access to /login1.php until the vendor issues an update
CVE-2026-105172
Detection coverage 2
Detect CVE-2026-105172 Exploitation - SQL Injection in /login1.php
highDetects attempts to exploit CVE-2026-105172 by checking for common SQL injection syntax within the 'User' parameter of /login1.php
Detects CVE-2026-105183 Exploitation - Remote SQL Injection
highDetects exploitation attempts against CVE-2026-105183 by identifying common SQL injection patterns in the schedid parameter directed at the /admin/confirm.php endpoint.
Detection queries are available on the platform. Get full rules →