Impact
An input processing flaw in the SourceCodester Simple and Nice Shopping Cart Script 1.0 file /admin/girlsproductdeletequery.php allows a crafted user_id value to be inserted directly into a database query. This missing validation permits an attacker to perform SQL injection, which can read, modify, or delete arbitrary data in the underlying MySQL database.
Affected Systems
The vulnerability affects installations of SourceCodester Simple and Nice Shopping Cart Script version 1.0 that include the unpatched girlsproductdeletequery.php file. No additional versions or configurations are listed as affected in the available data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The description states that the exploitation is remote and can be achieved via a standard HTTP request; however, the documentation does not explicitly clarify whether authentication is required to reach the affected endpoint. Because the script resides in the admin area, it is possible that privileged access is needed, but this requirement is not confirmed in the provided information.
OpenCVE Enrichment