Impact
A vulnerability located in the online examination and learning management system enables an attacker to manipulate the class_group parameter within the view_students.php page, allowing the procurement of data that is normally restricted. The flaw permits an unauthorized user to bypass normal access controls, effectively gaining privilege to read protected student information. The weakness is classified under CWE-285 for improper authorization and CWE-639 for misuse of privileged operations, and directly threatens confidentiality and integrity of student records.
Affected Systems
The exposed system is the SourceCodester Online Examination & Learning Management System, with the affected build reported as version 1.0. Administrators should verify whether their instance uses this version or contains the vulnerable view_students.php module. Any deployed instance that has not been updated to a secure release may be susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability, and the exploit probability is not documented, with no listing in CISA KEV. Attack can be performed remotely by supplying a crafted class_group value to the web application, implying that an unauthenticated or low-privileged threat actor can trigger the unauthorized access. While there are no known public exploits, the remote nature and lack of a user interface restriction make it a realistic target for threat actors seeking to harvest student data.
OpenCVE Enrichment