Description
A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection enabling unauthorized database access
Action: Patch Immediately
AI Analysis

Impact

A flaw in SourceCodester Online Faculty Clearance System 1.0 allows a remote attacker to manipulate the ID parameter in delete_requirement.php, resulting in an SQL injection. The weakness is an improper neutralization of input (CWE-74) during web page generation and improper neutralization of special elements used in SQL statements (CWE-89). This flaw can enable the adversary to read, modify, or delete records in the underlying database, leading to data disclosure or corruption.

Affected Systems

The vulnerability exists in the Release 1.0 of SourceCodester Online Faculty Clearance System, specifically within the delete_requirement.php file that handles the ID argument. All deployments running this version are potentially affected.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the EPSS score is < 1%, indicating a very low but nonzero likelihood of exploitation. The vulnerability is publicly disclosed and can be exploited remotely via a crafted request. It is not listed in the CISA KEV catalog. The attack vector, inferred from the description, is remote URL manipulation and does not require authentication, raising the chance that attackers could readily compromise the system.

Generated by OpenCVE AI on September 17, 2026 at 18:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor-released patch or upgrade to the latest version of Online Faculty Clearance System.
  • Restrict access to delete_requirement.php to authorized users only, adding authentication and role checks.
  • Sanitize the ID parameter and use parameterized queries to eliminate unsanitized SQL injection risk.

Generated by OpenCVE AI on September 17, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Title SourceCodester Online Faculty Clearance System delete_requirement.php sql injection
First Time appeared Sourcecodester
Sourcecodester online Faculty Clearance System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:online_faculty_clearance_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Faculty Clearance System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Faculty Clearance System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T16:59:08.719Z

Reserved: 2026-09-14T07:16:04.845Z

Link: CVE-2026-90876

cve-icon Vulnrichment

Updated: 2026-09-16T16:59:03.459Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T04:18:20.230

Modified: 2026-09-16T17:18:18.667

Link: CVE-2026-90876

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T05:15:16Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')