Impact
A flaw in Code‑Projects Assessment Management 1.0 enables an attacker to manipulate the squestions[] parameter in the /lecturer/marking-scheme.php endpoint, resulting in a classic SQL injection condition. This weakness arises from insufficient input validation (CWE‑74) and (CWE‑89). Successful exploitation could allow an attacker to read, modify, or delete records in the underlying database, potentially exposing student data, grades, or other confidential information.
Affected Systems
The Code‑Projects Assessment Management application, version 1.0, is affected; no data regarding other versions or related products is provided.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. An EPSS score of <1% suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is remote, originating from an external system, and a concept exploit has been published, implying the possibility of real‑world attacks.
OpenCVE Enrichment