Impact
The vulnerability is an unsanitized SQL query in the ID parameter of the delete_teacher.php script within SourceCodester's Class and Exam Timetabling System. An attacker can supply crafted input to inject arbitrary SQL commands, potentially retrieving, modifying, or deleting data from the system’s database. The flaw allows remote exploitation over the web, enabling unauthorized access or alteration of sensitive information such as teacher records and scheduling data.
Affected Systems
SourceCodester Class and Exam Timetabling System version 1.0 is affected. The problematic code resides in the delete_teacher.php file, which can be accessed via the web interface of the application.
Risk and Exploitability
The issue carries a CVSS score of 6.9, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread documented exploitation at this time. Nevertheless, the attack vector is remote and the exploit code has been publicly released, increasing the likelihood that attackers may target exposed instances of the system.
OpenCVE Enrichment