A vulnerability identified as critical has been detected in itsourcecode Online Student Enrollment System 1.0. This impacts an unknown function of the file assignInstructorSubjects.php. This manipulation of the argument subjcode causes sql injection.

This vulnerability is tracked as CVE-2026-36233. The attack is possible to be carried out remotely. No exploit exists.