Description
A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation of the argument haydi results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Assess Impact
AI Analysis

Impact

A flaw in SourceCodester Online Faculty Clearance System version 1.0 allows an attacker to manipulate the haydi argument in update_requirement_status.php, leading to arbitrary SQL injection. This vulnerability can be exploited remotely via a payload that may read, modify, or delete data from the underlying database, potentially exposing sensitive student or faculty information and compromising the integrity of the clearance process.

Affected Systems

The bug affects SourceCodester Online Faculty Clearance System version 1.0. The vulnerable code resides in the update_requirement_status.php script.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate impact. The EPSS score is <1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is remotely exploitable and publicly disclosed, an attacker can launch attacks from outside the trusted network. Exploitation would require constructing a valid HTTP request with a malicious haydi value; successful exploitation would give the attacker full control over database queries.

Generated by OpenCVE AI on September 17, 2026 at 19:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Identify all installations of the Online Faculty Clearance System 1.0 and confirm whether the vulnerable update_requirement_status.php file is present.
  • Apply any vendor‑supplied patch or upgrade to a newer, unvulnerable version if SourceCodester has released an update.
  • If no patch is available, modify the application to use parameterized queries or stored procedures, ensuring the haydi input is properly sanitized before being incorporated into SQL statements.
  • Restrict direct web access to update_requirement_status.php by enforcing authentication and authorization checks or moving the script outside the web‑root if it is not intended for public access.

Generated by OpenCVE AI on September 17, 2026 at 19:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation of the argument haydi results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Title SourceCodester Online Faculty Clearance System update_requirement_status.php sql injection
First Time appeared Sourcecodester
Sourcecodester online Faculty Clearance System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:online_faculty_clearance_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Faculty Clearance System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Faculty Clearance System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:58:29.851Z

Reserved: 2026-09-14T07:16:08.391Z

Link: CVE-2026-90877

cve-icon Vulnrichment

Updated: 2026-09-15T13:58:24.927Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T04:18:20.450

Modified: 2026-09-15T14:37:14.523

Link: CVE-2026-90877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')