Impact
A flaw in the Title parameter of /admin/add_activity.php in Society Management System 1.0 permits an attacker to inject arbitrary SQL statements. This vulnerability can be leveraged remotely and can lead to reading, altering, or deleting database contents, thereby compromising the confidentiality, integrity, and availability of the system’s data.
Affected Systems
The vulnerability affects itsourcecode’s Society Management System version 1.0. No other product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability. The EPSS score of less than 1 percent suggests a low current exploitation likelihood, but the public nature of the exploit and remote attack vector mean that an attacker could still gain significant access if the system is not patched. The vulnerability is not listed in the CISA KEV catalog, but organizations using the affected version should treat it as a security concern and apply mitigations as soon as possible.
OpenCVE Enrichment