CVE-2026-4236

A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=add. Such manipulation of the argument txtsearch/deptname/name leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Configurations

No configuration.

History

16 Mar 2026, 14:20

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:20

Updated : 2026-03-16 14:53


NVD link : CVE-2026-4236

Mitre link : CVE-2026-4236

CVE.ORG link : CVE-2026-4236


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')