Impact
The SourceCodester School Registration and Fee System 1.0 contains a vulnerability in the /bilal/save_class.php script. A malicious user can send a crafted Category parameter that is incorporated directly into an SQL statement, allowing injection of arbitrary SQL code. The flaw permits remote attackers to read sensitive database data or modify records, and it can be triggered without authentication if the endpoint is publicly reachable.
Affected Systems
The affected product is SourceCodester School Registration and Fee System version 1.0. No other vendors or versions are currently documented as impacted.
Risk and Exploitability
The CVSS base score of 6.9 indicates moderate severity. The EPSS score is less than 1%, suggesting a very low likelihood of exploitation at this time, yet the vulnerability is publicly disclosed and example exploits are available. Attackers could remotely send a crafted HTTP request to /bilal/save_class.php from any networked machine, potentially bypassing authentication if the application is exposed to the internet. The risk is realistic for publicly accessible installations.
OpenCVE Enrichment