Description
A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Apply Patch
AI Analysis

Impact

The SourceCodester School Registration and Fee System 1.0 contains a vulnerability in the /bilal/save_class.php script. A malicious user can send a crafted Category parameter that is incorporated directly into an SQL statement, allowing injection of arbitrary SQL code. The flaw permits remote attackers to read sensitive database data or modify records, and it can be triggered without authentication if the endpoint is publicly reachable.

Affected Systems

The affected product is SourceCodester School Registration and Fee System version 1.0. No other vendors or versions are currently documented as impacted.

Risk and Exploitability

The CVSS base score of 6.9 indicates moderate severity. The EPSS score is less than 1%, suggesting a very low likelihood of exploitation at this time, yet the vulnerability is publicly disclosed and example exploits are available. Attackers could remotely send a crafted HTTP request to /bilal/save_class.php from any networked machine, potentially bypassing authentication if the application is exposed to the internet. The risk is realistic for publicly accessible installations.

Generated by OpenCVE AI on September 15, 2026 at 16:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update SourceCodester School Registration and Fee System to a patched version that eliminates the injection point or apply the vendor patch.
  • Modify the code to sanitize the Category input and use prepared statements or parameterized queries to prevent injection.
  • Configure the database user used by the application to have only the minimum permissions required, reducing the potential impact of an injection.

Generated by OpenCVE AI on September 15, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Title SourceCodester School Registration and Fee System save_class.php sql injection
First Time appeared Sourcecodester
Sourcecodester school Registration And Fee System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:school_registration_and_fee_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester school Registration And Fee System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester School Registration And Fee System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T17:23:21.182Z

Reserved: 2026-09-12T10:58:38.383Z

Link: CVE-2026-90526

cve-icon Vulnrichment

Updated: 2026-09-14T17:23:16.179Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T14:16:50.660

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90526

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:45:06Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')