Impact
A flaw in an undisclosed function of adminHome.php lets an attacker manipulate the social_insta argument to craft a SQL injection. The vulnerability allows remote execution of arbitrary SQL statements, which can expose, alter, or delete sensitive data from the underlying database. The impact is confined to the database accessed by the application, but the malicious queries could provide the adversary with read or write privileges over stored information.
Affected Systems
The affected product is projectworlds Online Art Gallery Shop Project version 1.0. The vulnerability resides in the back‑end code of the /admin/adminHome.php page, a management interface used by site administrators.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and no EPSS value is published, so the current exploitation probability is unknown. The vulnerability is not listed in CISA KEV, suggesting no large‑scale coordinated exploitation yet. Inferred from the description, the attack vector is remote; an attacker can send a crafted request to the admin endpoint and trigger the injection. Successful exploitation could allow an attacker to gain unauthorized database access and potentially elevate privileges within the application.
OpenCVE Enrichment