Sceawere

Vulnerability Detail

CVE-2026-102913UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Car Driving School Management System

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
5h ago
Vendor
SourceCodester
Product
Car Driving School Management System
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-30T05:16:44.160Z",
  "pubdate": "2026-09-30T05:16:44.160Z",
  "executiveSummary": "A critical SQL injection vulnerability has been identified in the SourceCodester Car Driving School Management System 1.0, specifically within the save_enrollment function located in /classes/Master.php.\nThe vulnerability arises from the improper sanitization and validation of user-supplied input before it is incorporated into database queries.\nAn unauthenticated remote attacker can exploit this flaw to execute arbitrary SQL commands, potentially leading to unauthorized data exfiltration, database modification, or complete compromise of the underlying data store.\nGiven that proof-of-concept exploit code has been publicly disclosed, the risk of exploitation is elevated.\nOrganizations deploying this software are exposed to significant security risks, including the potential breach of sensitive student and system information. Immediate action is required to secure the affected endpoints.",
  "technicalDetails": "The vulnerability resides in the server-side processing of the save_enrollment function within the /classes/Master.php file. This component fails to adequately parameterize or escape input data, allowing an attacker to inject malicious SQL syntax into the query execution flow.\nThe root cause is the direct concatenation of unvalidated HTTP request parameters into database query strings. By manipulating the input vectors associated with the enrollment process, an attacker can break out of the intended query context and append or substitute malicious SQL statements.\nThe attack flow commences with the attacker crafting an HTTP request directed at the /classes/Master.php?f=save_enrollment endpoint. By injecting SQL meta-characters (such as single quotes or comment markers) into the parameters processed by this function, the attacker alters the logic of the backend SQL execution.\nThe vulnerability allows for blind or error-based SQL injection, enabling the attacker to infer database structure, contents, and metadata. In successful exploitation scenarios, an attacker can bypass security controls to read sensitive tables, modify administrative user credentials, or delete records. Furthermore, if the database configuration permits, the injection might be leveraged to achieve command execution at the database server level.\nThe exploit is remotely accessible, requiring no prior authentication or administrative privileges to trigger the flaw, thereby increasing the attack surface to any network-connected entity capable of reaching the web application. Because the exploit logic is publicly available, threat actors can leverage automated scripts to identify and compromise vulnerable instances rapidly.\nPost-exploitation impact includes full loss of confidentiality, integrity, and availability of the database. The attacker can exfiltrate enrollment data, sensitive personally identifiable information (PII) of students, and administrative credentials, facilitating lateral movement within the hosting environment."
}
CVE-2026-102913: SQL Injection in Car Driving School Management System (HIGH Severity, CVSS: 7.3) | Sceawere