A vulnerability labeled as critical has been found in SourceCodester Online Thesis Archiving System 1.0. Affected by this vulnerability is an unknown functionality of the file /otas/view_archive.php. The manipulation results in sql injection.

This vulnerability is reported as CVE-2026-36948. The attack can be launched remotely. No exploit exists.