PT-2026-91856 · Sourcecodester · Online Faculty Clearance System
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester Online Faculty Clearance System version 1.0
Description
An issue exists in the
/update requirement status.php endpoint where manipulation of the haydi variable allows for remote SQL injection. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.Recommendations
Update SourceCodester Online Faculty Clearance System version 1.0 to a version that contains a fix for this issue.
As a temporary workaround, restrict access to the
/update requirement status.php file to minimize the risk of exploitation.Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Online Faculty Clearance System