Metrics
Affected Vendors & Products
Wed, 15 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SQL Injection in Online Student Enrollment System 1.0 Allows Arbitrary Database Access |
Tue, 14 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:itsourcecode:online_student_enrollment_system:1.0:*:*:*:*:*:*:* |
Tue, 14 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SQL Injection via Unvalidated subjcode Parameter in scheduleSubList.php of itsourcecode Online Student Enrollment System |
Tue, 14 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 13 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SQL Injection via Unvalidated subjcode Parameter in scheduleSubList.php of itsourcecode Online Student Enrollment System | |
| Weaknesses | CWE-89 |
Mon, 13 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Itsourcecode
Itsourcecode online Student Enrollment System |
|
| Vendors & Products |
Itsourcecode
Itsourcecode online Student Enrollment System |
Fri, 10 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-14T14:04:25.315Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36235
Updated: 2026-04-14T14:04:12.420Z
Status : Analyzed
Published: 2026-04-10T15:16:25.077
Modified: 2026-04-14T17:40:30.570
Link: CVE-2026-36235
No data.
OpenCVE Enrichment
Updated: 2026-04-15T16:00:07Z