Impact
The vulnerability exists in the /admin/core/drop_user.php component of SourceCodester Student Result Management System 1.0. By manipulating the ID argument, an attacker can trigger a denial of service condition, leading to the unavailability of the system for legitimate users. The weakness is classified as CWE‑404 and the scale of impact is moderate as indicated by a CVSS score of 6.9.
Affected Systems
The only affected product listed is the Student Result Management System by SourceCodester, version 1.0. No other versions or variants were identified in the current data.
Risk and Exploitability
The CVSS score of 6.9 categorises the risk as moderate, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not currently listed in CISA's KEV catalog, and the publicly available exploit demonstrates remote execution, but the CVE does not specify whether authentication is required. The overall threat level therefore remains moderate, but because the impact is system downtime, it is important to remediate promptly.
OpenCVE Enrichment