Description
A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection
Action: Immediate Patch
AI Analysis

Impact

A flaw exists in the SourceCodester School Registration and Fee System 1.0 specifically in the delete_stud.php script. By manipulating the selector[] argument, an attacker can inject arbitrary SQL, underlying database. This flaw falls under the classic injection weakness classes CWE‑74 and CWE‑89 and can compromise the confidentiality and integrity of student registration data.

Affected Systems

The affected asset is the SourceCodester School Registration and Fee System version 1.0. No other product versions have been reported affected, so vulnerabilities are confined to that release of the application.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. EPSS score < 1% shows a low likelihood of exploitation, but the flaw has been publicly disclosed, suggesting exploit code may be available. The attack vector is remote, relying on a web request to delete_stud.php; it can be carried out by any user able to reach the endpoint. Based on the description, it is inferred that low privilege or unauthenticated access might be sufficient if the endpoint is not protected.

Generated by OpenCVE AI on September 15, 2026 at 16:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑released patch or newer version of the School Registration and Fee System that sanitizes selector[] input and uses prepared statements.
  • If no patch exists, restrict or block access to delete_stud.php or enforce robust authentication and authorization before allowing the endpoint to process requests.
  • Implement server‑side validation to ensure selector[] contains only expected numeric identifiers and reject any requests that do not match that pattern.

Generated by OpenCVE AI on September 15, 2026 at 16:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Title SourceCodester School Registration and Fee System delete_stud.php sql injection
First Time appeared Sourcecodester
Sourcecodester school Registration And Fee System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:school_registration_and_fee_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester school Registration And Fee System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester School Registration And Fee System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-20T00:35:31.744Z

Reserved: 2026-09-12T09:27:26.042Z

Link: CVE-2026-90515

cve-icon Vulnrichment

Updated: 2026-09-20T00:30:56.545Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T12:17:15.147

Modified: 2026-09-20T01:16:32.200

Link: CVE-2026-90515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')