{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/online-admission-system-1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:itsourcecode:online_admission_system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-105172"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Online Admission System (1.0)"],"_cs_severities":["high"],"_cs_tags":["sqli","web-vulnerability","sql-injection","cve"],"_cs_type":"threat","_cs_vendors":["itsourcecode"],"content_html":"\u003cp\u003eCVE-2026-105172 is a high-severity SQL injection vulnerability affecting version 1.0 of the itsourcecode Online Admission System. The flaw resides within the /login1.php script, specifically in the processing of the 'User' argument. An unauthenticated remote attacker can supply crafted SQL payloads within this parameter to manipulate backend database queries. This vulnerability allows for unauthorized data extraction, modification, or bypass of authentication mechanisms. Public exploit code for this vulnerability is currently available, increasing the risk of active exploitation by opportunistic actors. Organizations using this software should restrict access to the application or apply compensating controls at the web application firewall level until a patch is available.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify systems running itsourcecode Online Admission System 1.0.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST or GET request targeting the /login1.php endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects malicious SQL syntax into the 'User' parameter.\u003c/li\u003e\n\u003cli\u003eThe vulnerable application passes the unsanitized 'User' input directly to the SQL query.\u003c/li\u003e\n\u003cli\u003eThe backend database executes the injected command with application-level privileges.\u003c/li\u003e\n\u003cli\u003eAttacker exfiltrates sensitive database content or bypasses login controls to gain unauthorized access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability can lead to complete compromise of the application database, including the theft of administrative credentials and student personal data. Given the availability of public exploits, the potential for automated exploitation is high, and organizations deploying this system are at significant risk of data exfiltration and integrity loss.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy a web application firewall (WAF) rule to block requests containing SQL injection patterns directed at /login1.php.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for HTTP requests to /login1.php where the 'User' parameter contains SQL keywords like 'UNION', 'SELECT', or '--'.\u003c/li\u003e\n\u003cli\u003eRestrict external network access to the Online Admission System interface until the vendor provides a remediation or patch.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-05T03:43:46Z","date_published":"2026-10-05T01:43:15Z","id":"https://feed.craftedsignal.io/briefs/2026-10-online-admission-sqli/","summary":"CVE-2026-105172 is a remote SQL injection vulnerability in itsourcecode Online Admission System 1.0, reachable via the User parameter in /login1.php, for which public exploit code is available.","title":"SQL Injection Vulnerability in itsourcecode Online Admission System","url":"https://feed.craftedsignal.io/briefs/2026-10-online-admission-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Online Admission System (1.0)","version":"https://jsonfeed.org/version/1.1"}