Impact
The CodeAstro Ecommerce Website 1.0 is vulnerable to SQL injection. This flaw originates allowing a malicious actor to embed arbitrary SQL statements. Based on the description, it is inferred that an attacker could read, modify, or delete records in the underlying database. The vulnerability is remote, as it can be triggered by any network capable of sending POST requests.
Affected Systems
The affected product is CodeAstro Ecommerce Website version 1.0. The flaw resides in the file /customer/confirm.php and has no other affected versions documented. Users running this version should be aware that the vulnerability exists in the default installation.
Risk and Exploitability
The CVSS score of 5.3 denotes medium severity. The EPSS score is < 1%, signifying a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, but publicly available exploit code exists, increasing the likelihood of real-world attacks. Accordingly, the attack can be performed remotely by an unauthenticated user, which, based on the description, is inferred to be possible, though no credentials are required. The impact is determined by the success of the SQL injection, potentially granting access to sensitive data or altering transaction integrity.
OpenCVE Enrichment