Impact
A vulnerability in the User Account Update component of SourceCodester Class and Exam Timetabling System 1.0 allows an attacker to manipulate the id/username argument in /admin/edit_user_account.php, resulting in improper authorization. This flaw permits the attacker to modify or reset the credentials of arbitrary user accounts without possessing legitimate administrative privileges, effectively enabling an account takeover scenario.
Affected Systems
The affected product is SourceCodester Class and Exam Timetabling System version 1.0, specifically the edit_user_account.php script in the admin section. No other versions were identified as vulnerable in the supplied data.
Risk and Exploitability
With a CVSS score of 5.3, the flaw poses a moderate severity risk. The exploitable endpoint can be accessed over the network, and the vulnerability has been publicly disclosed, suggesting that attackers may already be attempting to abuse it. Although the EPSS score is not available and the vulnerability is not listed in CISA KEV, the remote nature and lack of internal protections mean that organizations running the affected application should treat it as a potential threat. An attacker would need to know valid user identifiers or guess them, but the lack of authorization controls makes the attack straightforward once access is obtained.
OpenCVE Enrichment