HarborGuard / CVE
Back to search
CRITICALCVE-2026-36235Published Modified CNA mitre

CVE-2026-36235: A SQL injection vulnerability was found in the scheduleSubList

A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation.

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • n/a / n/a
    n/a
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
CVE-2026-36235: A SQL injection vulnerability was found in the scheduleSubList | HarborGuard CVE