Impact
A flaw in SourceCodester Class and Exam Timetabling System 1.0 allows an attacker to manipulate the "course" argument in modal_add_course2.php. The unchecked value is passed directly to the mysqli_query function, giving the attacker the ability to inject arbitrary SQL commands. This can lead to unauthorized data disclosure, modification, or deletion, directly compromising the confidentiality and integrity of the database.
Affected Systems
The vulnerability affects the SourceCodester Class and Exam Timetabling System, version 1.0, as distributed by SourceCodester. No other versions are listed as affected in the available data.
Risk and Exploitability
The assigned CVSS score of 6.9 indicates moderate severity, but the exposed web endpoint allows remote exploitation, and public information about a working exploit is available. Because the EPSS score is not provided and the vulnerability is not in the CISA KEV catalog, the likelihood of exploitation is uncertain; however, the remote nature and public disclosure suggest that attackers could readily target any deployed instance.
OpenCVE Enrichment