Impact
The vulnerability allows attackers to inject arbitrary SQL through the email and password parameters in employer/login.php. The description states that manipulating these arguments leads to SQL injection, enabling remote exploitation. No further details about the specific data that could be accessed or modified are given.
Affected Systems
Affected product: code‑projects Internship Management System version 1.0. The flaw resides in the Employer Login Endpoint component.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at the time of analysis. The flaw is not listed in the CISA KEV catalog. The description indicates that remote exploitation is possible, meaning an attacker can send crafted requests to the login endpoint over the network. Successful exploitation could allow execution of arbitrary SQL commands against the backend database, exposing or altering data.
OpenCVE Enrichment