Impact
The flaw resides in SourceCodester Class and Exam Timetabling System version 1.0, specifically within the code of /admin/session.php. By manipulating the ID argument, an attacker can bypass authentication checks, resulting in missing authorization. This vulnerability enables a remote actor to gain unauthorized access to administrative functions or sensitive data that should otherwise be protected.
Affected Systems
The affected product is the SourceCodester Class and Exam Timetabling System, version 1.0. No alternative versions or updates are listed, and the vulnerability details apply to the existing installation of this product.
Risk and Exploitability
With a CVSS score of 6.9, the risk is considered moderate. The exploit is available publicly and can be launched remotely by altering the ID parameter in web requests. Because EPSS information is not available and the vulnerability is not listed in CISA's KEV catalog, the likelihood of exploitation remains uncertain but the public availability of the exploit code elevates the potential threat. Official remediation is not documented, so administrators should treat the issue as a serious privilege escalations risk until a fix or mitigation becomes available.
OpenCVE Enrichment