Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in savestud.php via the parameters fname, lname, and studentclass.
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in updateclass.php via the parameter classname.
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /saveuser.php via the parameter status.
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in updatepassword.php via the parameter newpassword.