Impact
The vulnerability resides in the Master.php save_enrollment function of SourceCodester Car Driving School Management System. By manipulating input parameters, an attacker can inject arbitrary SQL code, potentially gaining unauthorized data access, modification, or deletion. This flaw is a classic SQL injection, categorized under CWE-74 and CWE-89, and can be triggered remotely through the system's web interface.
Affected Systems
The affected application is SourceCodester Car Driving School Management System version 1.0. No other versions or additional system components are listed as impacted. The vulnerability originates from an unvalidated or insufficiently sanitized input within the mentioned file in the application.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and there is no EPSS score available. The flaw is not listed in the CISA KEV catalog. Attackers can reach the vulnerable endpoint from outside the network, meaning exploitability is high once the flaw is identified. No publicly disclosed patch exists, so the risk remains until a fix is applied.
OpenCVE Enrichment