PatchSiren cyber security CVE debrief
CVE-2026-105186 itsourcecode CVE debrief
A SQL injection vulnerability exists in itsourcecode Online Admission System 1.0, specifically in the /new.php file. The vulnerability is triggered by manipulating the schedid argument. This issue can be exploited remotely. The exploit has been made public. Defenders should assess exposure and prioritize verification and mitigation. The vulnerability's impact is currently assessed as low with a CVSS score of 2.1. However, the exploit has been made public, increasing the urgency for defenders to verify the presence of this vulnerability in their systems and apply necessary mitigations.
- Vendor
- itsourcecode
- Product
- Online Admission System
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-05
Who should care
Defenders responsible for the itsourcecode Online Admission System 1.0 should assess exposure and prioritize verification and mitigation. The vulnerability's impact is currently assessed as low with a CVSS score of 2.1. However, the exploit has been made public, increasing the urgency for defenders to verify the presence of this vulnerability in their systems and apply necessary mitigations. Defenders should prioritize verifying the presence of this in 1.
Why it matters
Defenders should care about CVE-2026-105186 because it represents a SQL injection vulnerability in the itsourcecode Online Admission System 1.0, which can be exploited remotely. The vulnerability's impact is currently assessed as low with a CVSS score of 2.1. However, the exploit has been made public, increasing the urgency for defenders to verify the presence of this vulnerability in their systems and apply necessary mitigations.
- Potential for unauthorized data access
- Possible disruption of system operations
- Need for input validation and sanitization
- Verification of system logs for exploitation attempts
Technical summary
The vulnerability exists in the /new.php file of the itsourcecode Online Admission System 1.0. An attacker can exploit this by manipulating the schedid argument, leading to SQL injection. This issue can be exploited remotely. The exploit has been made public. Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations as available. The vulnerability's impact is currently assessed as low with a CVSS score of 2.1. However, the exploit has been made public, increasing the urgency for defenders to verify the presence of this vulnerability in their systems and apply necessary mitigations.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations as available.
Recommended defensive actions
- Verify the presence of the vulnerable /new.php file in the itsourcecode Online Admission System 1.0
- Check for and apply any available patches or updates from the vendor
- Implement input validation and sanitization for the schedid argument
- Monitor system logs for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the scope of affected systems and versions is not clearly defined. The vulnerability exists in the /new.php file of the itsourcecode Online Admission System 1.0. An attacker can exploit this by manipulating the schedid argument, leading to SQL injection. Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations as available. The exploit has been made public, increasing the urgency for action.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105186 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105186
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105186 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105186
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ltranquility/submit/issues/27
-
Source reference
Unverified legacy reference
URL: https://itsourcecode.com/
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-105186
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/971469
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413423
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413423/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.