Impact
The login.php handler in code‑projects Online Job Portal 1.0 fails to sanitise the txtUser and txtPass parameters, allowing an attacker to inject arbitrary SQL statements. This flaw, identified as CWE‑74 and CWE‑89, can be exploited remotely via the web interface.
Affected Systems
Version 1.0 of the code‑projects Online Job Portal is affected, and no other releases or products are listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.9 places this flaw in the moderate severity range, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, further reducing the likelihood of widespread attacks. Nevertheless, an attacker who can reach the publicly exposed login page could submit malicious credentials to execute arbitrary SQL commands.
OpenCVE Enrichment