A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that attackers can inject malicious code via the parameter "subjcode" and use it directly in SQL queries without the need for appropriate cleaning or validation.
CVE-2026-36233
NONE
EPSS 0.04%
Updated Apr 10, 2026
PHP
CVE Details
CVE ID
CVE-2026-36233
Published Date
Apr 10, 2026
Vendor
PHP
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.04%
Likelihood of exploitation in next 30 days
Percentile:
12.2th percentile (higher than 12.2% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory