Impact
The vulnerability exists in the login.php file of the Kusalkasilva Learning‑Management‑System. The mysql_error function processes the username and password parameters without proper sanitization, allowing attackers to inject arbitrary SQL. This flaw is listed as CWE‑74 and CWE‑89 and can be exploited remotely to read, alter, or delete data held by the system. The CVSS score of 6.9 indicates a medium severity when the application is exposed, and attackers could potentially gain unauthorized access to user accounts or obtain sensitive data.
Affected Systems
Affected systems comprise all deployments of the Kusalkasilva Learning‑Management‑System that include the vulnerable commit ffeb873f8803f1e9664384ff75000c7da45466d2. Continuous delivery with rolling releases means that the exact targeted release is not specified, and no patched or fixed versions have been released yet. Every installation using the public code base before the update is considered vulnerable.
Risk and Exploitability
The vulnerability is exploitable over the network, and the public disclosure indicates that exploits are available, although the EPSS value is not disclosed and the issue is not in the KEV catalog. The lack of a vendor patch combined with the remote attack vector raises the risk level for applications exposed to the internet. Organizations should treat this as a medium‑to‑high risk until a proper fix or mitigations are applied.
OpenCVE Enrichment