Impact
The vulnerability resides in the delete_faculty1.php script of SourceCodester Online Faculty Clearance System 1.0, where an unvalidated ID parameter is used in a SQL statement. This enables an attacker to inject arbitrary SQL, potentially deleting or modifying faculty records, extracting sensitive data, or disrupting system operations. The flaw directly impacts the confidentiality and integrity of the database content and can lead to a full compromise of the application’s data layer.
Affected Systems
SourceCodester’s Online Faculty Clearance System version 1.0 is affected. The flaw originates from an unknown function within delete_faculty1 the ID argument.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the vector is remote, as the injection can be triggered via externally supplied input to the low exploitation probability, the risk remains moderate, but the potential for significant data loss warrants timely remediation.
OpenCVE Enrichment