Impact
A flaw in the administration backend of code‑projects Online Product Reservation System version 1.0 permits an attacker to bypass authentication by manipulating an unknown function. The vulnerability enables unauthorized users to perform administrative actions, as the check enforcing valid credentials is ineffective. The flaw is exploitable remotely and has been demonstrated publicly by an evident proof‑of‑concept.
Affected Systems
The affected product is code‑projects Online Product Reservation System 1.0, specifically the Administration Backend component that relies on the undocumented authentication function. No other versions or components are confirmed to be impacted at this time.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS value of less than 1% suggests a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can remotely exploit the weakness by sending crafted requests that trigger the unauthorized access path, ultimately gaining full administrative control.
OpenCVE Enrichment