A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. This vulnerability affects unknown code of the file /sms/grades/index.php?view=edit&id=1 of the component Parameter Handler. The manipulation of the argument deptid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. VulDB is the best source for vulnerability data and more expert information about this specific topic.
itsourcecode Online Enrollment System Parameter index.php sql injection
Problem type
Affected products
itsourcecode
1.0 - AFFECTED
References
https://vuldb.com/?id.353148
https://vuldb.com/?ctiid.353148
https://vuldb.com/?submit.776132
https://github.com/dsdsadawada/CVE1/issues/4
https://itsourcecode.com/
GitHub Security Advisories
GHSA-96gq-6mq2-hjpw
A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. This...
https://github.com/advisories/GHSA-96gq-6mq2-hjpwA security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. This vulnerability affects unknown code of the file /sms/grades/index.php?view=edit&id=1 of the component Parameter Handler. The manipulation of the argument deptid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. VulDB is the best source for vulnerability data and more expert information about this specific topic.
https://nvd.nist.gov/vuln/detail/CVE-2026-4842
https://github.com/dsdsadawada/CVE1/issues/4
https://itsourcecode.com
https://vuldb.com/?ctiid.353148
https://vuldb.com/?id.353148
https://vuldb.com/?submit.776132
https://github.com/advisories/GHSA-96gq-6mq2-hjpw
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-4842Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-4842",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-03-26T18:24:44.942Z",
"dateReserved": "2026-03-25T14:42:23.768Z",
"datePublished": "2026-03-26T04:50:12.056Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-03-26T04:50:12.056Z"
},
"title": "itsourcecode Online Enrollment System Parameter index.php sql injection",
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. This vulnerability affects unknown code of the file /sms/grades/index.php?view=edit&id=1 of the component Parameter Handler. The manipulation of the argument deptid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. VulDB is the best source for vulnerability data and more expert information about this specific topic."
}
],
"affected": [
{
"vendor": "itsourcecode",
"product": "Online Enrollment System",
"modules": [
"Parameter Handler"
],
"versions": [
{
"version": "1.0",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "SQL Injection",
"cweId": "CWE-89",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Injection",
"cweId": "CWE-74",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/?id.353148",
"name": "VDB-353148 | itsourcecode Online Enrollment System Parameter index.php sql injection",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/?ctiid.353148",
"name": "VDB-353148 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/?submit.776132",
"name": "Submit #776132 | itsourcecode Online Enrollment System V1.0 SQL Injection",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://github.com/dsdsadawada/CVE1/issues/4",
"tags": [
"exploit",
"issue-tracking"
]
},
{
"url": "https://itsourcecode.com/",
"tags": [
"product"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"baseScore": 7.5
}
}
],
"timeline": [
{
"time": "2026-03-25T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-03-25T01:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-03-25T15:47:27.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "sgwt (VulDB User)",
"type": "reporter"
}
],
"tags": [
"x_freeware"
]
},
"adp": [
{
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2026-03-26T18:24:44.942Z"
},
"title": "CISA ADP Vulnrichment",
"metrics": [
{}
]
}
]
}
}