Impact
A vulnerability exists in SourceCodester School Registration and Fee System version 1.0 that allows an attacker to inject arbitrary SQL through the parameter named Status in the file save_stud.php. If exploited, this flaw can enable the attacker to read sensitive data or modify database records. The weakness is consistent with CWE-74 (Improper Neutralization of Untrusted Input) and CWE-89 (SQL Injection).
Affected Systems
The affected product is SourceCodester School Registration and Fee System 1.0. Any deployment of this version is vulnerable. The attack surface is the web interface that accepts the Status parameter, which is typically available on the publicly accessible site. Users should verify that their instances are running this specific version and that the endpoint is reachable from the network.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity flaw, and the EPSS score is < 1%, and it is not listed in the CISA publicly documented, the risk remains until a vendor release addresses the flaw or users implement mitigation measures.
OpenCVE Enrichment