Impact
Affected by a SQL injection flaw in the edit_rooma.php script, where a manipulated ID argument allows attackers to execute arbitrary SQL statements. This vulnerability can lead to unauthorized data disclosure, modification, or deletion, and potentially full compromise of the application’s database. The issue is classified as CWE-74 and CWE-89, reflecting malformed input handling and SQL injection weaknesses.
Affected Systems
Affected systems are users of SourceCodester Class and Exam Timetabling System version 1.0. No other versions are listed as impacted, so only installations of the 1.0 release are considered at risk.
Risk and Exploitability
Risk assessment shows a CVSS score of 6.9, indicating moderate severity. The EPSS score is below 1%, meaning public exploitation is currently uncommon, and it is not in the CISA KEV catalog. However, the vulnerability remains exploitable remotely, and publicly disclosed exploits exist, so the risk to organizations hosting the application is real for exposed servers.
OpenCVE Enrichment