Impact
A flaw exists in the /admin/login.php script of SourceCodester Simple and Nice Shopping Cart Script. The Username parameter is not sanitized, allowing injection of arbitrary SQL commands into the database query. This vulnerability can enable an attacker to execute unintended SQL statements, potentially exposing, modifying, or deleting data within the application’s database.
Affected Systems
The vulnerability affects SourceCodester Simple and Nice Shopping Cart Script. No specific release or version has been identified as impacted; the flaw resides in the Admin Login component of the script.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score is less than 1%, implying a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the publicly accessible /admin/login.php endpoint; exploit code has been released, confirming that remote exploitation is possible.
OpenCVE Enrichment