Impact
The vulnerability resides in the edit_exam.php page of SourceCodester Class and Exam Timetabling System 1.0. By manipulating the ID parameter, an attacker can inject arbitrary SQL statements that are executed against the database. This flaw is identified as CWE‑74 (Improper Neutralization of Input During Web Page Generation) and CWE‑89 (Improper Neutralization of Special Elements used in an SQL Command). The outcome is that an attacker could read, modify or delete data held in the application database, compromising confidentiality, integrity and potentially availability of the system.
Affected Systems
Only SourceCodester Class and Exam Timetabling System 1.0 is listed as affected. No other vendors or product versions are indicated as vulnerable, and the scope appears limited to the edit_exam.php module.
Risk and Exploitability
With a CVSS score of 6.9 the flaw is considered medium severity, and the EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation. The exploit has been publicly disclosed and can be conducted remotely, but the description does not clarify whether authentication is required, introducing uncertainty about the required attacker context. Since the vulnerability is not listed in the CISA KEV catalog, additional heightened awareness or mitigation guidance is not available, but the potential impact warrants prompt action.
OpenCVE Enrichment