Impact
An unknown function in the Student Result Management System 1.0 update_smtp.php allows manipulation that bypasses intended access controls. The vulnerability aligns with improper privilege management and improper access control weaknesses. The flaw may permit the alteration of SMTP settings or the use of application email capabilities for unauthorized activity. The issue is catalogued under CWE-266 and CWE-284.
Affected Systems
The affected product is SourceCodester Student Result Management System version 1.0. Vulnerability resides in the core update_smtp.php script that handles SMTP configuration. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 denotes a moderate severity. Exploit probability is very low, with an EPSS score below 1%. The flaw is not reported in the CISA KEV catalog. The description states the flaw can be triggered remotely, and publicly disclosed exploit demonstrates the possibility of manipulating the target function. The risk remains moderate, but the lack of widespread exploitation does not diminish the need for corrective action.
OpenCVE Enrichment