A SQL injection vulnerability (CVE-2026-36232) exists in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0, where the 'classId' parameter is directly concatenated into SQL queries without sanitization or validation. The vulnerability carries a CVSS score of 9.8 (CRITICAL), with a network-based attack vector requiring no authentication, low complexity, and no user interaction, resulting in complete compromise of confidentiality, integrity, and availability. While the vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no evidence of active exploitation in the wild, the high CVSS score and low technical barrier to exploitation present significant risk to affected systems. Organizations running the vulnerable version should prioritize patching or implementing network-level controls to restrict access to the affected application component.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:itsourcecode:online_student_enrollment_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.