Impact
A flaw in SourceCodester Online Faculty Clearance System version 1.0 allows an attacker to manipulate the haydi argument in update_requirement_status.php, leading to arbitrary SQL injection. This vulnerability can be exploited remotely via a payload that may read, modify, or delete data from the underlying database, potentially exposing sensitive student or faculty information and compromising the integrity of the clearance process.
Affected Systems
The bug affects SourceCodester Online Faculty Clearance System version 1.0. The vulnerable code resides in the update_requirement_status.php script.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate impact. The EPSS score is <1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is remotely exploitable and publicly disclosed, an attacker can launch attacks from outside the trusted network. Exploitation would require constructing a valid HTTP request with a malicious haydi value; successful exploitation would give the attacker full control over database queries.
OpenCVE Enrichment