Loading market data...
← Back to CVE feed

CVE-2026-36235

UNKNOWN View on NVD ↗

Description

A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation.

Published: Apr 10, 2026 15:16 UTC Modified: Apr 10, 2026 15:16 UTC