Impact
The vulnerability resides in the admin index functionality of CodeAstro Simple Loan Management System 1.0. Manipulating the ‘g_name’ argument permits a classic SQL injection, which may let an attacker execute arbitrary SQL against the underlying database. The flaw is a classic injection weakness (CWE‑74 and CWE‑89) and can be exploited from any remote location, with an exploit already released publicly. If successfully leveraged, the attacker can read, modify, or delete sensitive data stored in the application’s database.
Affected Systems
The affected product is CodeAstro Simple Loan Management System version 1.0. The vulnerability is triggered via the file /admin/index.php when the g_name query string parameter is supplied without proper validation.
Risk and Exploitability
The CVSS score of 5.3 classifies the issue as medium severity, and the EPSS score is currently unavailable. The vulnerability is not listed in the CISA KEV catalog. Because the attack vector is remote and the exploit is publicly available, an attacker with network access to the application can exploit it. Successful exploitation requires only the ability to send crafted requests to /admin/index.php, and there are no additional complex prerequisites noted in the description.
OpenCVE Enrichment