A vulnerability has been identified in SourceCodester Simple Traffic Offense System version 1.0. The flaw resides in the file saveuser.php within the User Creation component. By manipulating the 'position' argument, an attacker can bypass authentication controls entirely. The vulnerability is remotely exploitable without requiring prior authentication or user interaction. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a PHP-based web application commonly used for traffic violation management. The missing authentication flaw could allow unauthorized users to create or manipulate user accounts. This represents a significant access control weakness with potential for full system compromise. Organizations using this software should apply mitigations or remove public exposure immediately.