Impact
A vulnerability exists in attacker to inject arbitrary SQL through the "Current" parameter. The database, resulting in a classic SQL injection flaw, a CWE-89 vulnerability, and also a loss of protection of input context, a CWE-74 weakness. An attacker who can reach the employer/details/change_password.php endpoint can exploit this remotely. It is inferred that this could enable an adversary to read, modify, or delete data in the database, but the description does not explicitly confirm the extent of data that can be accessed or altered.
Affected Systems
The vulnerable product is code‑projects Internship Management System version 1.0. All installations of this version that expose the employer/details/change_password.php endpoint are affected.
Risk and Exploitability
5.3 indicates medium severity, and the EPSS score of less than 1% suggests a low probability of spontaneous exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs to send a crafted request to the exposed Change Password endpoint, which is reachable over the network, making the attack path straightforward. Successful exploitation would provide the attacker with unauthorized access to the database, allowing potential manipulation of stored data.
OpenCVE Enrichment