Impact
A flaw exists in the /admin/login.php script of SourceCodester Simple and Nice Shopping Cart Script that allows an attacker to inject arbitrary SQL through an unsanitized Username field. The injected code can manipulate database queries, potentially exposing, modifying, or deleting sensitive information and elevating the attacker’s privileges. The vulnerability maps to CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and CWE-74 (Improper Encoding or Escaping).
Affected Systems
Affected versions are not specified in the available data. The flaw resides in the Admin Login component of SourceCodester Simple and Nice Shopping Cart Script, but no particular release has been identified as impacted.
Risk and Exploitability
The CVSS score of 6.9 reflects a moderate severity. An EPSS score of less than 1% indicates a very low yet non‑zero chance of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the publicly accessible /admin/login.php endpoint; exploit code has been released, confirming that remote exploitation is feasible.
OpenCVE Enrichment