Description
A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-09-30
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote SQL Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Master.php save_enrollment function of SourceCodester Car Driving School Management System. By manipulating input parameters, an attacker can inject arbitrary SQL code, potentially gaining unauthorized data access, modification, or deletion. This flaw is a classic SQL injection, categorized under CWE-74 and CWE-89, and can be triggered remotely through the system's web interface.

Affected Systems

The affected application is SourceCodester Car Driving School Management System version 1.0. No other versions or additional system components are listed as impacted. The vulnerability originates from an unvalidated or insufficiently sanitized input within the mentioned file in the application.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and there is no EPSS score available. The flaw is not listed in the CISA KEV catalog. Attackers can reach the vulnerable endpoint from outside the network, meaning exploitability is high once the flaw is identified. No publicly disclosed patch exists, so the risk remains until a fix is applied.

Generated by OpenCVE AI on September 30, 2026 at 06:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor release or patch that addresses the SQL injection in the Master.php save_enrollment function.
  • If no patch is available, implement strict input validation and parameterized queries to neutralize SQL injection vectors.
  • Restrict the database user's privileges so that even if injection occurs, the attacker can only perform SELECT operations and cannot alter or drop tables.
  • Enable logging and monitor for abnormal query patterns to detect possible exploitation attempts.

Generated by OpenCVE AI on September 30, 2026 at 06:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Title SourceCodester Car Driving School Management System Master.php save_enrollment sql injection
First Time appeared Sourcecodester
Sourcecodester car Driving School Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:car_driving_school_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester car Driving School Management System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Car Driving School Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T04:15:08.214Z

Reserved: 2026-09-29T18:29:37.209Z

Link: CVE-2026-102913

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T05:16:44.160

Modified: 2026-09-30T05:16:44.160

Link: CVE-2026-102913

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T05:30:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')