Skip to content
Threat Feed
high threat exploited

SQL Injection Vulnerability in itsourcecode Online Admission System

CVE-2026-105172 is a remote SQL injection vulnerability in itsourcecode Online Admission System 1.0, reachable via the User parameter in /login1.php, for which public exploit code is available.

CVE search metadata

CVE search record: CVE-2026-105172. Severity: high. CVSS: 7.3. KEV: no. Product: Online Admission System (1.0). Brief: SQL Injection Vulnerability in itsourcecode Online Admission System. Brief link: https://feed.craftedsignal.io/briefs/2026-10-online-admission-sqli/

What's new

  • 1. added detection rule: Detects CVE-2026-105183 Exploitation - Remote SQL Injection Oct 5, 03:43 via nvd

CVE-2026-105172 is a high-severity SQL injection vulnerability affecting version 1.0 of the itsourcecode Online Admission System. The flaw resides within the /login1.php script, specifically in the processing of the 'User' argument. An unauthenticated remote attacker can supply crafted SQL payloads within this parameter to manipulate backend database queries. This vulnerability allows for unauthorized data extraction, modification, or bypass of authentication mechanisms. Public exploit code for this vulnerability is currently available, increasing the risk of active exploitation by opportunistic actors. Organizations using this software should restrict access to the application or apply compensating controls at the web application firewall level until a patch is available.

Attack Chain

  1. Attacker performs reconnaissance to identify systems running itsourcecode Online Admission System 1.0.
  2. Attacker crafts an HTTP POST or GET request targeting the /login1.php endpoint.
  3. Attacker injects malicious SQL syntax into the 'User' parameter.
  4. The vulnerable application passes the unsanitized 'User' input directly to the SQL query.
  5. The backend database executes the injected command with application-level privileges.
  6. Attacker exfiltrates sensitive database content or bypasses login controls to gain unauthorized access.

Impact

Successful exploitation of this vulnerability can lead to complete compromise of the application database, including the theft of administrative credentials and student personal data. Given the availability of public exploits, the potential for automated exploitation is high, and organizations deploying this system are at significant risk of data exfiltration and integrity loss.

Recommendation

  1. Deploy a web application firewall (WAF) rule to block requests containing SQL injection patterns directed at /login1.php.
  2. Audit web server logs for HTTP requests to /login1.php where the 'User' parameter contains SQL keywords like 'UNION', 'SELECT', or '--'.
  3. Restrict external network access to the Online Admission System interface until the vendor provides a remediation or patch.

Immediate actions

Implement WAF blocking rules for /login1.php SQLi patterns

SOC 24h

Threat Hunt

Search web logs for 200 or 500 status codes on /login1.php with signs of SQLi in the query string

T1190 high medium confidence hunt now

Data: Web server access logs

Mitigations

Restrict access to /login1.php until the vendor issues an update

immediate IT Operations

CVE-2026-105172

Detection coverage 2

Detect CVE-2026-105172 Exploitation - SQL Injection in /login1.php

high

Detects attempts to exploit CVE-2026-105172 by checking for common SQL injection syntax within the 'User' parameter of /login1.php

sigma tactics: initial_access techniques: T1190 sources: webserver

Detects CVE-2026-105183 Exploitation - Remote SQL Injection

high

Detects exploitation attempts against CVE-2026-105183 by identifying common SQL injection patterns in the schedid parameter directed at the /admin/confirm.php endpoint.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →