Impact
The vulnerability is an SQL injection in the sy parameter within /archive4.php of SourceCodester Class and Exam Timetabling System 1.0. By manipulating that argument, an attacker can inject arbitrary SQL, enabling unauthorized database access, data exfiltration, or modification. The weakness falls under CWE-74 and CWE-89.
Affected Systems
SourceCodester Class and Exam Timetabling System version 1.0. No other versions are listed as affected.
Risk and Exploitability
The CVSS score is 6.9, indicating moderate severity. EPSS data is unavailable, but the exploit has been publicly released, suggesting a higher likelihood of attack. It is not listed in CISA KEV. The flaw can be exploited remotely via a crafted HTTP request, giving the attacker direct access to the underlying database.
OpenCVE Enrichment