Impact
The vulnerability occurs in the edit_exam.php file of SourceCodester Class and Exam Timetabling System version 1.0. By manipulating the ID parameter, an attacker can inject arbitrary SQL statements, which may allow unauthorized reading, modification, or deletion of database content. This is a classic SQL injection flaw identified as CWE-74 and CWE-89. The description indicates that the attack can not be sure whether authentication is required of the flaw.
Affected Systems
Only SourceCodester Class and Exam Timetabling System version 1.0 is listed as affected. No other products or versions are indicated as vulnerable, and the scope appears limited to the edit_exam.php module.
Risk and Exploitability
With a CVSS score of 6.9 the flaw is considered medium severity. The EPSS score of less than 1% shows a very low but non‑zero probability of exploitation. The publicly disclosed exploit demonstrates that the flaw can be exploited remotely, yet the lack of confirmed authentication requirements introduces some uncertainty. As the vulnerability is not yet part of the CISA KEV catalog, it does not benefit from heightened awareness or mitigation guidance, but the potential impact warrants prompt action.
OpenCVE Enrichment