Impact
The vulnerability is a SQL injection flaw in the delbaptism.php entry point of the Baptism Information Management System. Manipulating the ID argument allows an attacker to inject arbitrary SQL code, enabling unauthorized reading or modification of baptism records. The flaw is exploitable remotely via the web interface and has a publicly available exploit, meaning that the potential impact includes loss of confidentiality and integrity of sensitive personal data.
Affected Systems
The affected product is itsourcecode Baptism Information Management System, version 1.0. No other affected versions are listed in the supplied information. The flaw resides specifically within the delbaptism.php component.
Risk and Exploitability
The CVSS score is 6.9, denoting moderate severity. EPSS is not available, but the presence of a public exploit indicates a tangible risk. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach the vulnerable endpoint remotely over HTTP by supplying a crafted ID parameter, which the application fails to sanitize.
OpenCVE Enrichment