PT-2026-30405 · Itsourcecode · Online Enrollment System

Hlg123

·

Published

2026-04-05

·

Updated

2026-04-05

·

CVE-2026-5534

CVSS v2.0

7.5

High

AV:N/AC:L/Au:N/C:P/I:P/A:P
A vulnerability was identified in itsourcecode Online Enrollment System 1.0. This affects an unknown function of the file /sms/user/index.php?view=edit&id=10 of the component Parameter Handler. Such manipulation of the argument USERID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-5534

Affected Products

Online Enrollment System