<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Online Admission System (1.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/online-admission-system-1.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 01:43:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/online-admission-system-1.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection Vulnerability in itsourcecode Online Admission System</title><link>https://feed.craftedsignal.io/briefs/2026-10-online-admission-sqli/</link><pubDate>Mon, 05 Oct 2026 01:43:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-online-admission-sqli/</guid><description>CVE-2026-105172 is a remote SQL injection vulnerability in itsourcecode Online Admission System 1.0, reachable via the User parameter in /login1.php, for which public exploit code is available.</description><content:encoded><![CDATA[<p>CVE-2026-105172 is a high-severity SQL injection vulnerability affecting version 1.0 of the itsourcecode Online Admission System. The flaw resides within the /login1.php script, specifically in the processing of the 'User' argument. An unauthenticated remote attacker can supply crafted SQL payloads within this parameter to manipulate backend database queries. This vulnerability allows for unauthorized data extraction, modification, or bypass of authentication mechanisms. Public exploit code for this vulnerability is currently available, increasing the risk of active exploitation by opportunistic actors. Organizations using this software should restrict access to the application or apply compensating controls at the web application firewall level until a patch is available.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs reconnaissance to identify systems running itsourcecode Online Admission System 1.0.</li>
<li>Attacker crafts an HTTP POST or GET request targeting the /login1.php endpoint.</li>
<li>Attacker injects malicious SQL syntax into the 'User' parameter.</li>
<li>The vulnerable application passes the unsanitized 'User' input directly to the SQL query.</li>
<li>The backend database executes the injected command with application-level privileges.</li>
<li>Attacker exfiltrates sensitive database content or bypasses login controls to gain unauthorized access.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability can lead to complete compromise of the application database, including the theft of administrative credentials and student personal data. Given the availability of public exploits, the potential for automated exploitation is high, and organizations deploying this system are at significant risk of data exfiltration and integrity loss.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Deploy a web application firewall (WAF) rule to block requests containing SQL injection patterns directed at /login1.php.</li>
<li>Audit web server logs for HTTP requests to /login1.php where the 'User' parameter contains SQL keywords like 'UNION', 'SELECT', or '--'.</li>
<li>Restrict external network access to the Online Admission System interface until the vendor provides a remediation or patch.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>sqli</category><category>web-vulnerability</category><category>sql-injection</category><category>cve</category></item></channel></rss>