A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
cve CVE-2026-105253 2 sources, 2 claims · Watch
NVD writes:
A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. the claim
A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. the claim
What it is to other things
In words only, so not counted until a person confirms one:
| affects | itsourcecode/online_admission_system_projectNVD says “itsourcecode · Online Admission System Project” |
| made_by | itsourcecodeNVD says “itsourcecode” |
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Cvss cvss | GitHub advisories | 7.3receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105253",
"cvss": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 5.5,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-74",
"name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
}
],
"description": "A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.",
"ghsa_id": "GHSA-3x76-4f4r-r8gx",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-3x76-4f4r-r8gx",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-3x76-4f4r-r8gx"
},
{
"type": "CVE",
"value": "CVE-2026-105253"
}
],
"nvd_published_at": "2026-10-05T09:17:11Z",
"published_at": "2026-10-05T09:31:54Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-105253",
"https://github.com/maryhu821/Submit/issues/1",
"https://itsourcecode.com",
"https://vuldb.com/cve/CVE-2026-105253",
"https://vuldb.com/submit/977177",
"https://vuldb.com/vuln/413462",
"https://vuldb.com/vuln/413462/cti",
"https://github.com/advisories/GHSA-3x76-4f4r-r8gx"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue...",
"type": "unreviewed",
"updated_at": "2026-10-05T09:32:02Z",
"url": "https://api.github.com/advisories/GHSA-3x76-4f4r-r8gx",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Cvss cvss | NVD | 7.3receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"cpes": [
"cpe:2.3:a:itsourcecode:online_admission_system_project:*:*:*:*:*:*:*:*"
],
"product": "Online Admission System Project",
"vendor": "itsourcecode",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"source": "cna@vuldb.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized."
}
],
"id": "CVE-2026-105253",
"lastModified": "2026-10-05T09:17:11.753",
"metrics": {
"cvssMetricV2": [
{
"acInsufInfo": false,
"baseSeverity": "HIGH",
"cvssData": {
"accessComplexity": "LOW",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5,
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"version": "2.0"
},
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"source": "cna@vuldb.com",
"type": "Secondary",
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.4,
"source": "cna@vuldb.com",
"type": "Primary"
}
],
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "PROOF_OF_CONCEPT",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "cna@vuldb.com",
"type": "Secondary"
}
]
},
"published": "2026-10-05T09:17:11.753",
"references": [
{
"source": "cna@vuldb.com",
"url": "https://github.com/maryhu821/Submit/issues/1"
},
{
"source": "cna@vuldb.com",
"url": "https://itsourcecode.com/"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/cve/CVE-2026-105253"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/submit/977177"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/vuln/413462"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/vuln/413462/cti"
}
],
"sourceIdentifier": "cna@vuldb.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-89"
}
],
"source": "cna@vuldb.com",
"type": "Primary"
}
]
}
} | — |
| Cwe cwe | GitHub advisories | CWE-74receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105253",
"cvss": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 5.5,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-74",
"name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
}
],
"description": "A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.",
"ghsa_id": "GHSA-3x76-4f4r-r8gx",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-3x76-4f4r-r8gx",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-3x76-4f4r-r8gx"
},
{
"type": "CVE",
"value": "CVE-2026-105253"
}
],
"nvd_published_at": "2026-10-05T09:17:11Z",
"published_at": "2026-10-05T09:31:54Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-105253",
"https://github.com/maryhu821/Submit/issues/1",
"https://itsourcecode.com",
"https://vuldb.com/cve/CVE-2026-105253",
"https://vuldb.com/submit/977177",
"https://vuldb.com/vuln/413462",
"https://vuldb.com/vuln/413462/cti",
"https://github.com/advisories/GHSA-3x76-4f4r-r8gx"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue...",
"type": "unreviewed",
"updated_at": "2026-10-05T09:32:02Z",
"url": "https://api.github.com/advisories/GHSA-3x76-4f4r-r8gx",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Product product | NVD | Online Admission System Projectreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"cpes": [
"cpe:2.3:a:itsourcecode:online_admission_system_project:*:*:*:*:*:*:*:*"
],
"product": "Online Admission System Project",
"vendor": "itsourcecode",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"source": "cna@vuldb.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized."
}
],
"id": "CVE-2026-105253",
"lastModified": "2026-10-05T09:17:11.753",
"metrics": {
"cvssMetricV2": [
{
"acInsufInfo": false,
"baseSeverity": "HIGH",
"cvssData": {
"accessComplexity": "LOW",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5,
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"version": "2.0"
},
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"source": "cna@vuldb.com",
"type": "Secondary",
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.4,
"source": "cna@vuldb.com",
"type": "Primary"
}
],
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "PROOF_OF_CONCEPT",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "cna@vuldb.com",
"type": "Secondary"
}
]
},
"published": "2026-10-05T09:17:11.753",
"references": [
{
"source": "cna@vuldb.com",
"url": "https://github.com/maryhu821/Submit/issues/1"
},
{
"source": "cna@vuldb.com",
"url": "https://itsourcecode.com/"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/cve/CVE-2026-105253"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/submit/977177"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/vuln/413462"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/vuln/413462/cti"
}
],
"sourceIdentifier": "cna@vuldb.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-89"
}
],
"source": "cna@vuldb.com",
"type": "Primary"
}
]
}
} | — |
| Severity severity | GitHub advisories | mediumreceipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-105253",
"cvss": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 5.5,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-74",
"name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
}
],
"description": "A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.",
"ghsa_id": "GHSA-3x76-4f4r-r8gx",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-3x76-4f4r-r8gx",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-3x76-4f4r-r8gx"
},
{
"type": "CVE",
"value": "CVE-2026-105253"
}
],
"nvd_published_at": "2026-10-05T09:17:11Z",
"published_at": "2026-10-05T09:31:54Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-105253",
"https://github.com/maryhu821/Submit/issues/1",
"https://itsourcecode.com",
"https://vuldb.com/cve/CVE-2026-105253",
"https://vuldb.com/submit/977177",
"https://vuldb.com/vuln/413462",
"https://vuldb.com/vuln/413462/cti",
"https://github.com/advisories/GHSA-3x76-4f4r-r8gx"
],
"repository_advisory_url": null,
"severity": "medium",
"source_code_location": "",
"summary": "A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue...",
"type": "unreviewed",
"updated_at": "2026-10-05T09:32:02Z",
"url": "https://api.github.com/advisories/GHSA-3x76-4f4r-r8gx",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Status status | NVD | Receivedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"cpes": [
"cpe:2.3:a:itsourcecode:online_admission_system_project:*:*:*:*:*:*:*:*"
],
"product": "Online Admission System Project",
"vendor": "itsourcecode",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"source": "cna@vuldb.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized."
}
],
"id": "CVE-2026-105253",
"lastModified": "2026-10-05T09:17:11.753",
"metrics": {
"cvssMetricV2": [
{
"acInsufInfo": false,
"baseSeverity": "HIGH",
"cvssData": {
"accessComplexity": "LOW",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5,
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"version": "2.0"
},
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"source": "cna@vuldb.com",
"type": "Secondary",
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.4,
"source": "cna@vuldb.com",
"type": "Primary"
}
],
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "PROOF_OF_CONCEPT",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "cna@vuldb.com",
"type": "Secondary"
}
]
},
"published": "2026-10-05T09:17:11.753",
"references": [
{
"source": "cna@vuldb.com",
"url": "https://github.com/maryhu821/Submit/issues/1"
},
{
"source": "cna@vuldb.com",
"url": "https://itsourcecode.com/"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/cve/CVE-2026-105253"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/submit/977177"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/vuln/413462"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/vuln/413462/cti"
}
],
"sourceIdentifier": "cna@vuldb.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-89"
}
],
"source": "cna@vuldb.com",
"type": "Primary"
}
]
}
} | — |
| Vendor vendor | NVD | itsourcecodereceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"cpes": [
"cpe:2.3:a:itsourcecode:online_admission_system_project:*:*:*:*:*:*:*:*"
],
"product": "Online Admission System Project",
"vendor": "itsourcecode",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"source": "cna@vuldb.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized."
}
],
"id": "CVE-2026-105253",
"lastModified": "2026-10-05T09:17:11.753",
"metrics": {
"cvssMetricV2": [
{
"acInsufInfo": false,
"baseSeverity": "HIGH",
"cvssData": {
"accessComplexity": "LOW",
"accessVector": "NETWORK",
"authentication": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5,
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"version": "2.0"
},
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"obtainAllPrivilege": false,
"obtainOtherPrivilege": false,
"obtainUserPrivilege": false,
"source": "cna@vuldb.com",
"type": "Secondary",
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.4,
"source": "cna@vuldb.com",
"type": "Primary"
}
],
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "PROOF_OF_CONCEPT",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "cna@vuldb.com",
"type": "Secondary"
}
]
},
"published": "2026-10-05T09:17:11.753",
"references": [
{
"source": "cna@vuldb.com",
"url": "https://github.com/maryhu821/Submit/issues/1"
},
{
"source": "cna@vuldb.com",
"url": "https://itsourcecode.com/"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/cve/CVE-2026-105253"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/submit/977177"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/vuln/413462"
},
{
"source": "cna@vuldb.com",
"url": "https://vuldb.com/vuln/413462/cti"
}
],
"sourceIdentifier": "cna@vuldb.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-89"
}
],
"source": "cna@vuldb.com",
"type": "Primary"
}
]
}
} | — |
vulnerability
| A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue affects some unknown processing of the file /admin/login1.php. This manipulation of the argument User causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. zetlyn/cve-nvd · 2026-10-05 | cvss 7.3 product Online Admission System Project status Received vendor itsourcecode | source |
| A vulnerability was determined in itsourcecode Online Admission System Project 1.0. This issue... zetlyn/cve-ghsa · 2026-10-05 | cvss 7.3 cwe CWE-74 severity medium | source |