A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element...
zetlyn/cve-ghsa vulnerability ghsa GHSA-r8wv-hwwh-9qgg cve CVE-2026-105183 known 2026-10-05
https://github.com/advisories/GHSA-r8wv-hwwh-9qgg
Properties
| cvss | 7.3receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105183",
"cvss": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 5.5,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-74",
"name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
}
],
"description": "A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is an unknown function of the file /admin/confirm.php. This manipulation of the argument schedid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.",
"ghsa_id": "GHSA-r8wv-hwwh-9qgg",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-r8wv-hwwh-9qgg",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-r8wv-hwwh-9qgg"
},
{
"type": "CVE",
"value": "CVE-2026-105183"
}
],
"nvd_published_at": "2026-10-05T03:16:38Z",
"published_at": "2026-10-05T03:30:27Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-105183",
"https://github.com/ltranquility/submit/issues/24",
"https://itsourcecode.com",
"https://vuldb.com/cve/CVE-2026-105183",
"https://vuldb.com/submit/971464",
"https://vuldb.com/vuln/413420",
"https://vuldb.com/vuln/413420/cti",
"https://github.com/advisories/GHSA-r8wv-hwwh-9qgg"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element...",
"type": "unreviewed",
"updated_at": "2026-10-05T03:30:33Z",
"url": "https://api.github.com/advisories/GHSA-r8wv-hwwh-9qgg",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|---|
| cwe | CWE-74receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105183",
"cvss": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 5.5,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-74",
"name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
}
],
"description": "A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is an unknown function of the file /admin/confirm.php. This manipulation of the argument schedid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.",
"ghsa_id": "GHSA-r8wv-hwwh-9qgg",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-r8wv-hwwh-9qgg",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-r8wv-hwwh-9qgg"
},
{
"type": "CVE",
"value": "CVE-2026-105183"
}
],
"nvd_published_at": "2026-10-05T03:16:38Z",
"published_at": "2026-10-05T03:30:27Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-105183",
"https://github.com/ltranquility/submit/issues/24",
"https://itsourcecode.com",
"https://vuldb.com/cve/CVE-2026-105183",
"https://vuldb.com/submit/971464",
"https://vuldb.com/vuln/413420",
"https://vuldb.com/vuln/413420/cti",
"https://github.com/advisories/GHSA-r8wv-hwwh-9qgg"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element...",
"type": "unreviewed",
"updated_at": "2026-10-05T03:30:33Z",
"url": "https://api.github.com/advisories/GHSA-r8wv-hwwh-9qgg",
"vulnerabilities": [],
"withdrawn_at": null
} |
| severity | mediumreceipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105183",
"cvss": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 5.5,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-74",
"name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
}
],
"description": "A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is an unknown function of the file /admin/confirm.php. This manipulation of the argument schedid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.",
"ghsa_id": "GHSA-r8wv-hwwh-9qgg",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-r8wv-hwwh-9qgg",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-r8wv-hwwh-9qgg"
},
{
"type": "CVE",
"value": "CVE-2026-105183"
}
],
"nvd_published_at": "2026-10-05T03:16:38Z",
"published_at": "2026-10-05T03:30:27Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-105183",
"https://github.com/ltranquility/submit/issues/24",
"https://itsourcecode.com",
"https://vuldb.com/cve/CVE-2026-105183",
"https://vuldb.com/submit/971464",
"https://vuldb.com/vuln/413420",
"https://vuldb.com/vuln/413420/cti",
"https://github.com/advisories/GHSA-r8wv-hwwh-9qgg"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element...",
"type": "unreviewed",
"updated_at": "2026-10-05T03:30:33Z",
"url": "https://api.github.com/advisories/GHSA-r8wv-hwwh-9qgg",
"vulnerabilities": [],
"withdrawn_at": null
} |
Text
A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element...
A weakness has been identified in itsourcecode Online Admission System 1.0. The affected element is an unknown function of the file /admin/confirm.php. This manipulation of the argument schedid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.