{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/car-driving-school-management-system-1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sourcecodester:car_driving_school_management_system:1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-102913"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Car Driving School Management System (1.0)"],"_cs_severities":["high"],"_cs_tags":["sql-injection","vulnerability","web-application"],"_cs_type":"threat","_cs_vendors":["SourceCodester"],"content_html":"\u003cp\u003eA security vulnerability identified as CVE-2026-102913 affects SourceCodester Car Driving School Management System version 1.0. The vulnerability resides in an unspecified function within the file '/classes/Master.php' specifically handled by the 'save_enrollment' parameter. An unauthenticated remote attacker can inject malicious SQL commands via this endpoint, manipulating the application database queries. Public exploit code for this vulnerability has been released, increasing the risk of active exploitation. Given the nature of the application and the availability of PoC scripts, defenders should prioritize patching or implementing mitigating controls to prevent unauthorized data exfiltration or database manipulation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to execute arbitrary SQL commands against the backend database. This may result in full unauthorized access to sensitive user data, enrollment information, or administrative credentials stored within the system. The impact is significant for organizations relying on this software for operational management, as it directly facilitates data breaches.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eImmediate action is required to secure vulnerable instances of the application.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEvaluate all internet-facing instances of SourceCodester Car Driving School Management System 1.0 for the presence of this vulnerability.\u003c/li\u003e\n\u003cli\u003eAs no patch is currently provided by the vendor, implement a Web Application Firewall (WAF) rule to inspect and block incoming HTTP requests to '/classes/Master.php' containing SQL injection patterns, specifically targeting the 'save_enrollment' parameter.\u003c/li\u003e\n\u003cli\u003eRestrict access to the application management modules via IP allowlisting or VPN requirements until a vendor-supplied patch is available.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T06:32:14Z","date_published":"2026-09-30T06:32:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102913/","summary":"SourceCodester Car Driving School Management System 1.0 is vulnerable to unauthenticated remote SQL injection via the save_enrollment function in Master.php, allowing potential unauthorized database access.","title":"SQL Injection Vulnerability in SourceCodester Car Driving School Management System","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102913/"}],"language":"en","title":"CraftedSignal Threat Feed - Car Driving School Management System (1.0)","version":"https://jsonfeed.org/version/1.1"}