Impact
A flaw in the source code of the file archive1.php enables an attacker to perform SQL injection by manipulating the "sy" argument. This allows the execution of arbitrary SQL statements, which could lead to unauthorized data disclosure, modification, or deletion by a remote actor. The impact is confined to the database accessed by the application, with no other claims of denial of service or privilege escalation in the description.
Affected Systems
The vulnerability affects the SourceCodester Class and Exam Timetabling System version 1.0, specifically the /archive1.php functionality. No other versions or components are listed as impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score is not provided. The vulnerability is not listed in the CISA KEV catalog. A remote attacker can exploit the flaw by sending a crafted HTTP request that includes a malicious "sy" value. Publicly available exploits suggest that the attack vector is a standard web-based input, and no additional conditions are described.
OpenCVE Enrichment