A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
SourceCodester Online Faculty Clearance System delete_faculty1.php sql injection
Problem type
Affected products
SourceCodester
1.0 - AFFECTED
References
https://vuldb.com/vuln/403587
https://vuldb.com/vuln/403587/cti
https://vuldb.com/cve/CVE-2026-91004
https://vuldb.com/submit/932333
https://github.com/zzjzzzj389/cve/issues/2
https://www.sourcecodester.com/
GitHub Security Advisories
GHSA-9pqw-f8g3-xhmj
A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The...
https://github.com/advisories/GHSA-9pqw-f8g3-xhmjA vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
https://nvd.nist.gov/vuln/detail/CVE-2026-91004
https://github.com/zzjzzzj389/cve/issues/2
https://vuldb.com/cve/CVE-2026-91004
https://vuldb.com/submit/932333
https://vuldb.com/vuln/403587
https://vuldb.com/vuln/403587/cti
https://www.sourcecodester.com
https://github.com/advisories/GHSA-9pqw-f8g3-xhmj
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-91004Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-91004",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-09-15T06:00:13.497Z",
"dateReserved": "2026-09-14T15:50:51.192Z",
"datePublished": "2026-09-15T06:00:13.497Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-09-15T06:00:13.497Z"
},
"title": "SourceCodester Online Faculty Clearance System delete_faculty1.php sql injection",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used."
}
],
"affected": [
{
"vendor": "SourceCodester",
"product": "Online Faculty Clearance System",
"cpes": [
"cpe:2.3:a:sourcecodester:online_faculty_clearance_system:*:*:*:*:*:*:*:*"
],
"versions": [
{
"version": "1.0",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "SQL Injection",
"cweId": "CWE-89",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Injection",
"cweId": "CWE-74",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/vuln/403587",
"name": "VDB-403587 | SourceCodester Online Faculty Clearance System delete_faculty1.php sql injection",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/vuln/403587/cti",
"name": "VDB-403587 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/cve/CVE-2026-91004",
"name": "CVE-2026-91004 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://vuldb.com/submit/932333",
"name": "Submit #932333 | SourceCodester Online Faculty Clearance System using PHP/MySQL with Source Code V1.0 OnlineClearance/delete_faculty1.php 1.0 SQL Injection",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://github.com/zzjzzzj389/cve/issues/2",
"tags": [
"exploit",
"issue-tracking"
]
},
{
"url": "https://www.sourcecodester.com/",
"tags": [
"product"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"baseScore": 7.5
}
}
],
"timeline": [
{
"time": "2026-09-14T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-09-14T02:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-09-14T17:56:07.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "plutoyrw (VulDB User)",
"type": "reporter"
}
],
"tags": [
"x_freeware"
]
}
}
}