Description
A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL injection allowing unauthorized database manipulation
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the delete_faculty1.php script of SourceCodester Online Faculty Clearance System 1.0, where an unvalidated ID parameter is used in a SQL statement. This enables an attacker to inject arbitrary SQL, potentially deleting or modifying faculty records, extracting sensitive data, or disrupting system operations. The flaw directly impacts the confidentiality and integrity of the database content and can lead to a full compromise of the application’s data layer.

Affected Systems

SourceCodester’s Online Faculty Clearance System version 1.0 is affected. The flaw originates from an unknown function within delete_faculty1 the ID argument.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the vector is remote, as the injection can be triggered via externally supplied input to the low exploitation probability, the risk remains moderate, but the potential for significant data loss warrants timely remediation.

Generated by OpenCVE AI on September 17, 2026 at 18:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or update to a fixed release when it becomes available
  • Implement input validation and parameterized queries for the ID variable in delete_faculty1.php
  • Restrict access to delete_faculty1.php to authenticated administrators only
  • Monitor database and application logs for anomalous SQL activity

Generated by OpenCVE AI on September 17, 2026 at 18:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Title SourceCodester Online Faculty Clearance System delete_faculty1.php sql injection
First Time appeared Sourcecodester
Sourcecodester online Faculty Clearance System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:online_faculty_clearance_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Faculty Clearance System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Faculty Clearance System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:51:39.901Z

Reserved: 2026-09-14T15:50:51.192Z

Link: CVE-2026-91004

cve-icon Vulnrichment

Updated: 2026-09-15T14:51:36.159Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T06:17:01.910

Modified: 2026-09-15T15:17:31.310

Link: CVE-2026-91004

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')