Skip to content
Threat Feed
high threat exploited

SQL Injection Vulnerability in SourceCodester Car Driving School Management System

SourceCodester Car Driving School Management System 1.0 is vulnerable to unauthenticated remote SQL injection via the save_enrollment function in Master.php, allowing potential unauthorized database access.

CVE search metadata

CVE search record: CVE-2026-102913. Severity: high. CVSS: 7.3. KEV: no. Product: Car Driving School Management System (1.0). Brief: SQL Injection Vulnerability in SourceCodester Car Driving School Management System. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102913/

A security vulnerability identified as CVE-2026-102913 affects SourceCodester Car Driving School Management System version 1.0. The vulnerability resides in an unspecified function within the file '/classes/Master.php' specifically handled by the 'save_enrollment' parameter. An unauthenticated remote attacker can inject malicious SQL commands via this endpoint, manipulating the application database queries. Public exploit code for this vulnerability has been released, increasing the risk of active exploitation. Given the nature of the application and the availability of PoC scripts, defenders should prioritize patching or implementing mitigating controls to prevent unauthorized data exfiltration or database manipulation.

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary SQL commands against the backend database. This may result in full unauthorized access to sensitive user data, enrollment information, or administrative credentials stored within the system. The impact is significant for organizations relying on this software for operational management, as it directly facilitates data breaches.

Recommendation

Immediate action is required to secure vulnerable instances of the application.

  • Evaluate all internet-facing instances of SourceCodester Car Driving School Management System 1.0 for the presence of this vulnerability.
  • As no patch is currently provided by the vendor, implement a Web Application Firewall (WAF) rule to inspect and block incoming HTTP requests to '/classes/Master.php' containing SQL injection patterns, specifically targeting the 'save_enrollment' parameter.
  • Restrict access to the application management modules via IP allowlisting or VPN requirements until a vendor-supplied patch is available.

Immediate actions

Deploy WAF rules to inspect POST/GET requests to /classes/Master.php for SQL syntax anomalies

SOC 24h

Mitigations

Restrict external network access to the application management endpoint until a fix is available

immediate IT Operations

CVE-2026-102913