Description
A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Immediate Patch
AI Analysis

Impact

A vulnerability exists in SourceCodester School Registration and Fee System version 1.0 that allows an attacker to inject arbitrary SQL through the parameter named Status in the file save_stud.php. If exploited, this flaw can enable the attacker to read sensitive data or modify database records. The weakness is consistent with CWE-74 (Improper Neutralization of Untrusted Input) and CWE-89 (SQL Injection).

Affected Systems

The affected product is SourceCodester School Registration and Fee System 1.0. Any deployment of this version is vulnerable. The attack surface is the web interface that accepts the Status parameter, which is typically available on the publicly accessible site. Users should verify that their instances are running this specific version and that the endpoint is reachable from the network.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity flaw, and the EPSS score is < 1%, and it is not listed in the CISA publicly documented, the risk remains until a vendor release addresses the flaw or users implement mitigation measures.

Generated by OpenCVE AI on September 15, 2026 at 17:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available vendor patch or newer release of SourceCodester School Registration and Fee System that fixes the SQL injection in save_stud.php.
  • If a patch is not available, restrict convert the code to use prepared statements to prevent arbitrary SQL execution.
  • Configure the web application firewall or equivalent controls to block requests containing suspicious characters or patterns in the Status

Generated by OpenCVE AI on September 15, 2026 at 17:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Title SourceCodester School Registration and Fee System save_stud.php sql injection
First Time appeared Sourcecodester
Sourcecodester school Registration And Fee System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:school_registration_and_fee_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester school Registration And Fee System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester School Registration And Fee System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:00:24.181Z

Reserved: 2026-09-12T09:27:22.627Z

Link: CVE-2026-90514

cve-icon Vulnrichment

Updated: 2026-09-15T13:47:36.349Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T11:17:00.423

Modified: 2026-09-15T15:17:27.933

Link: CVE-2026-90514

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:45:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')