Impact
A flaw exists in the edit_class2.php file of the SourceCodester Class and Exam Timetabling System that allows an attacker to manipulate the ID parameter and inject arbitrary SQL. The injection is achievable remotely via crafted web requests. By exploiting this vulnerability, an attacker could execute unauthorized SQL commands against the database, potentially compromising data integrity or confidentiality.
Affected Systems
SourceCodester Class and Exam Timetabling System version 1.0 is affected.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. With publicly available exploit code, the risk of exploitation is real. Attackers can trigger the vulnerability via a web request to edit_class2.php, using a manipulated ID value to execute arbitrary SQL commands. The likely attack vector is remote web access to the vulnerable endpoint.
OpenCVE Enrichment