Impact
A vulnerability in the CodeAstro Simple Pharmacy Management System, specifically in the product/view.php file, allows an attacker to manipulate the ID parameter and inject raw SQL. The flaw is an unsanitized input that can be leveraged to execute arbitrary database queries, potentially exposing sensitive pharmacy records or altering them. This consequence directly compromises confidentiality and integrity of the system’s data.
Affected Systems
The affected product is CodeAstro Simple Pharmacy Management System, version 1.0. The vulnerability resides in the view.php component that handles product display; no other versions or components were identified from the available data.
Risk and Exploitability
The CVSS score is 5.3, indicating a medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack is remote, driven by crafted input to the ID argument, and the exploit has already been publicly disclosed. While the likelihood of exploitation is uncertain without EPSS data, the mere existence of a publicly known SQL injection warrants attention.
OpenCVE Enrichment