Impact
The vulnerability is a classic SQL injection in the Category parameter of the /opils/admin/view_product.php file within SourceCodester Performance Indicator System 1.0. Exploiting this flaw can allow an attacker to retrieve, modify, or delete data from the underlying database without authorization, as the application fails to neutralize special characters in SQL queries. The weakness falls under CWE-74 (Improper Neutralization of Data for Use in an Expression) and CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).
Affected Systems
The affected system is SourceCodester Performance Indicator System, version 1.0, deployed on web servers that expose the /opils/admin/view_product.php administrative interface.
Risk and Exploitability
The described CVSS score of 5.3 indicates moderate severity. No EPSS value is available, but the advisory notes that the exploit is publicly known, suggesting a realistic chance of exploitation in the absence of mitigation. The vulnerability is not listed in the CISA KEV catalog. Attackers can perform the attack remotely by crafting a malicious HTTP request containing a specially crafted Category value that the server will inject into a database query.
OpenCVE Enrichment