Impact
The vulnerability resides in the login.php script of code-projects Online Music Site 1.0, where manipulating the username and password fields allows an attacker to inject arbitrary SQL statements. This flaw can enable unauthorized data access, modification, or deletion in the underlying database. The vulnerability is reported as exploitable remotely, meaning an attacker can trigger the injection without needing credential or local access.
Affected Systems
The affected product is code-projects’ Online Music Site version 1.0. No other versions or components are explicitly identified as vulnerable. The issue is specific to the login functionality on this platform.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate risk, and the EPSS score of less than 1% suggests low current exploitation likelihood. Although the vulnerability is not listed in CISA’s KEV catalog, the remote nature of the attack vector means an attacker could readily craft a malicious payload to exploit the site, potentially leading to unauthorized data exposure or compromise of the database.
OpenCVE Enrichment