Impact
The vulnerability resides in the delete_exam.php component of SourceCodester Syllabus‑Aligned Learning Management & Examination System 1.0, where the ID parameter can be manipulated to bypass authorization controls. By altering the ID argument, an attacker can delete examinations that they should not have permission to remove, compromising the integrity of the system’s data. This breach can affect any user who is authenticated to the application, and in principle can be exploited by remote actors with network access to the web application.
Affected Systems
SourceCodester Syllabus‑Aligned Learning Management & Examination System version 1.0 is impacted. No other product versions are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity for this IDOR flaw. Although an EPSS score is not available and the vulnerability is not listed in CISA KEV, the attack vector is remote because the flaw can be triggered over a network by sending a crafted request to delete_exam.php. The public disclosure of the exploit suggests that an attacker could leverage the faulty authorization logic to delete exams without proper privileges.
OpenCVE Enrichment