Impact
A remotely exploitable SQL injection flaw originates from the "period" argument in pay_report.php on the SourceCodester School Registration and Fee System version 1.0. The flaw allows an attacker to execute arbitrary SQL commands against the database, potentially compromising data confidentiality, integrity, and availability. The vulnerability is classified as CWE-74 and CWE-89.
Affected Systems
SourceCodester School Registration and Fee System version 1.0 is affected, specifically the pay_report.php script located in the /bilal/normal directory. The flaw can be triggered by any external client that can reach the application with crafted input in the period parameter.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. The EPSS score is less than 1%, suggesting a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The exploit is publicly available and can be initiated remotely without authentication, highlighting the need for timely remediation.
OpenCVE Enrichment