Impact
SourceCodester Modern Loan Management System 1.0 contains a SQL injection flaw in the ajaxData.php script, affecting the district_id, division_id, region_id, and ward_id parameters. This vulnerability can allow an attacker to cause the application to execute arbitrary SQL statements against the backend database. Based on the description, the impact could include unauthorized reading, modification, or deletion of data stored in the database, thereby compromising both confidentiality and integrity.
Affected Systems
The affected system is SourceCodester Modern Loan Management System 1.0. No other products or versions are listed, so the risk is confined to installations of this specific version of the software.
Risk and Exploitability
The EPSS score of < 1% indicates a very low exploitation probability at present, and the vulnerability is not yet listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote HTTP request to ajaxData.php containing malicious payloads in the district_id, division_id, region_id, and ward_id parameters. The flaw is exploitable remotely without local access and requires only unsanitized user input; no authentication is mentioned, which increases the ease of exploitation. The CVSS score of 9.8 classifies the vulnerability as Critical, confirming a high likelihood of unauthorized data disclosure or database compromise.
OpenCVE Enrichment