Impact
A flaw in the smarksrange[] parameter of the /lecturer/marking-scheme.php script allows an attacker to inject arbitrary SQL code into the application’s database. The vulnerability is identified as CWE-74 and CWE-89. If exploited, an attacker could read, modify, or delete database records, thereby compromising the confidentiality and integrity of the stored data.
Affected Systems
code-projects Assessment Management version 1.0 is affected. The flaw resides in the marking-scheme.php file accessed via the web interface. No other versions are mentioned, and the application uses a relational database.
Risk and Exploitability
The attack can be launched remotely over HTTP. The CVSS base score of 5.3 indicates moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. No authentication prerequisite is noted, which could broaden the potential impact.
OpenCVE Enrichment