Impact
A flaw exists in the SourceCodester School Registration and Fee System 1.0 specifically in the delete_stud.php script. By manipulating the selector[] argument, an attacker can inject arbitrary SQL, underlying database. This flaw falls under the classic injection weakness classes CWE‑74 and CWE‑89 and can compromise the confidentiality and integrity of student registration data.
Affected Systems
The affected asset is the SourceCodester School Registration and Fee System version 1.0. No other product versions have been reported affected, so vulnerabilities are confined to that release of the application.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. EPSS score < 1% shows a low likelihood of exploitation, but the flaw has been publicly disclosed, suggesting exploit code may be available. The attack vector is remote, relying on a web request to delete_stud.php; it can be carried out by any user able to reach the endpoint. Based on the description, it is inferred that low privilege or unauthenticated access might be sufficient if the endpoint is not protected.
OpenCVE Enrichment