Impact
A flaw in the SourceCodester Class and Exam Timetabling System allows an attacker to inject arbitrary SQL through manipulation of the ID argument in the /edit_subjecta.php script. This injection targets the database layer and can be performed over the network, resulting in potential disclosure, modification, or deletion of sensitive data. The vulnerability is classified as CWE-74 and CWE-89, reflecting unvalidated input and improper use of SQL statements.
Affected Systems
The affected product is SourceCodester Class and Exam Timetabling System, version 1.0. The flaw resides in the /edit_subjecta.php functionality and impacts any instance where this script is deployed.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity risk, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, and the attack vector is remote. However, because the flaw allows compromised SQL execution, the potential impact on confidentiality and integrity remains significant if exploited.
OpenCVE Enrichment