CVE-2026-90877: SourceCodester Online Faculty Clearance System update_requirement_status.php sql injection
A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /updaterequirementstatus.php. The manipulation of the argument haydi results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be launched remotely and requires no privileges or user interaction according to the supplied vector. Any reachable deployment of the affected application may be exposed if the vulnerable endpoint is accessible.
What input should be investigated when assessing exposure?
Review the /update_requirement_status.php endpoint and its handling of the haydi argument. The reported issue is SQL injection caused by manipulation of that argument.
Is public exploit code available?
Yes. The exploit has been made public and could be used, which increases the likelihood of attempted exploitation.