CVE-2026-36234

CRITICAL WAF: High
CVSS 9.8 Published: 2026-04-10
CWE-89

itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter.

WAF Coverage Analysis

SQL Injection High WAF Coverage

OWASP: A03:2021 Injection

942xxx - SQL Injection

Affected Software

VendorProductVersion
itsourcecodeonline_student_enrollment_system1.0

References

  • github.com (Exploit, Mitigation, Third Party Advisory)
Back to CVE Database