CVE-2026-91004: SourceCodester Online Faculty Clearance System delete_faculty1.php sql injection
Published Sep 15, 2026
·Updated
A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /deletefaculty1.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Sourcecodester Online Faculty Clearance System=1.0
Event History
Sep 15, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need an account or user interaction to exploit this issue?
No. The CVSS vector indicates no privileges are required and no user interaction is needed; the attack can be performed remotely.
2
How likely is exploitation in the near term?
A public exploit has been disclosed, and the CVSS assessment marks exploit maturity as proof-of-concept. Systems running the affected 1.0 release should be treated as exposed if the vulnerable endpoint is reachable.