CVE-2026-5650
A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/database/oas.sql. Performing a manipulation results in insecure storage of sensitive information. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.31%
- CWE
- CWE-922, CWE-200
- Published
- 2026-04-06
- Last modified
- 2026-04-06
Affected products
- code-projects Online Application System for Admission
Weakness type
Related vulnerabilities
- CVE-2026-44629 — Improper access control to the Synergis Softwire installation folder. This vulnerability affects...
- CVE-2026-20705 — Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform...
- CVE-2026-47362 — The Datadog Android application stores operationally sensitive content in plaintext SQLite...
- CVE-2026-46511 — HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
- CVE-2025-32751 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information...
- CVE-2025-32746 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information...
- CVE-2026-7257 — ** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the...
- CVE-2026-40868 — kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token