Impact
A SQL injection flaw exists in the edit_course1.php page of SourceCodester Class and Exam Timetabling System 1.0. The vulnerability originates when the ID parameter is manipulated, allowing an attacker to inject arbitrary sensitive of database records, or execution of unintended queries, thereby compromising data integrity and confidentiality.
Affected Systems
SourceCodester Class and Exam Timetabling System version 1.0 is affected. The flaw is limited to the edit_course1.php component and does not or later releases mentioned in the data.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, while the EPSS score of <1% suggests a low but nonzero exploitation probability. The vulnerability is publicly disclosed and is not listed in the CISA KEV catalog, implying no widespread attacks have been reported yet. The likely attack vector is a remote request to edit_course1.php with a crafted ID value; based on the description, it is inferred that no authentication is required for exploitation and that public internet access is sufficient.
OpenCVE Enrichment