CVE-2026-36232 PUBLISHED

Assigner: mitre
Reserved: 06.04.2026 Published: 10.04.2026 Updated: 10.04.2026

A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'classId' parameter from $_GET['classId'] is directly concatenated into the SQL query without any sanitization or validation.

Product Status

Vendor n/a
Product n/a
Versions
  • Version n/a is affected

References

Problem Types

  • n/a text