CRITICALAi
Verified
Global

NVD CRITICAL: CVE-2026-36232 — A SQL injection vulnerability was found in the instructorClasses.php file of its...

·Source: NIST NVD

Updated:

Executive Summary

A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'classId' parameter from $_GET['classId'] is directly concatenated into the SQL query without any sanitization or validation.

Analysis

A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'classId' parameter from $_GET['classId'] is directly concatenated into the SQL query without any sanitization or validation. CVSS Score: 9.8. Published: 2026-04-10T15:16:24.697.

Indicators of Compromise (1)

CVE (1)
CVE-2026-36232
Source Attribution

Originally published by NIST NVD on Apr 10, 2026. Verified by: NIST.

Related Threats