Impact
The flaw is located in the saveuser.php file of SourceCodester Simple Traffic Offense System 1.0. A missing authentication check allows an attacker to submit user creation requests without providing valid credentials. This missing authentication (CWE-287) and lack of any authentication enforcement (CWE-306) enable the creation of accounts that grant the attacker a foothold within the application, potentially leading to privilege escalation and further exploitation.
Affected Systems
Only the 1.0 release of SourceCodester Simple Traffic Offense System is listed as affected. No other product versions or downstream releases are cited, so any installation of that version remains vulnerable until remediation.
Risk and Exploitability
The vulnerability carries a CVSS base score of 6.9, indicating a moderate severity. EPSS data is not available and the flaw is not included in CISA’s KEV catalog, but a public exploit has already been disclosed. An attacker can initiate the exploit remotely by manipulating parameters sent to saveuser.php, creating new user accounts without authentication.
OpenCVE Enrichment