Impact
A flaw in SourceCodester Online Faculty Clearance System 1.0 allows a remote attacker to manipulate the ID parameter in delete_requirement.php, resulting in an SQL injection. The weakness is an improper neutralization of input (CWE-74) during web page generation and improper neutralization of special elements used in SQL statements (CWE-89). This flaw can enable the adversary to read, modify, or delete records in the underlying database, leading to data disclosure or corruption.
Affected Systems
The vulnerability exists in the Release 1.0 of SourceCodester Online Faculty Clearance System, specifically within the delete_requirement.php file that handles the ID argument. All deployments running this version are potentially affected.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score is < 1%, indicating a very low but nonzero likelihood of exploitation. The vulnerability is publicly disclosed and can be exploited remotely via a crafted request. It is not listed in the CISA KEV catalog. The attack vector, inferred from the description, is remote URL manipulation and does not require authentication, raising the chance that attackers could readily compromise the system.
OpenCVE Enrichment