Impact
A vulnerability in the SourceCodester Class and Exam Timetabling System 1.0 allows an attacker to manipulate the ID parameter in edit_schoolyr.php, resulting in a classic SQL injection flaw. The injection can be used to read, modify, or delete database records, potentially exposing sensitive student, faculty, or institutional data. This vulnerability is an example of CWE‑74 (Untrusted Control of Generation of SQL Statements) and CWE‑89 (SQL Injection).
Affected Systems
The affected product is SourceCodester Class and Exam Timetabling System 1.0. Any deployment of this version that includes the edit_schoolyr.php script is vulnerable, regardless of user authentication or network exposure.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium‑to‑high severity, and an EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is publicly exploitable and can be triggered remotely, yet the system is not listed in the CISA KEV catalog, so the known exploitation risk remains largely dependent on the attacker’s motivation and the value of the exposed data.
OpenCVE Enrichment