Impact
A security flaw has been discovered in CodeAstro Ecommerce Website 1.0 that allows manipulation of the delete_wishlist argument in the /customer/my_account.php?my_wishlist request, resulting in arbitrary SQL injection. The remote attacker can alter or read database contents, potentially compromising data integrity or confidentiality. The weakness is classified as CWE-74 and CWE-89, and a publicly released exploit confirms that attackers can launch the attack remotely.
Affected Systems
The flaw affects CodeAstro Ecommerce Website 1.0, specifically the delete_wishlist logic within the my_account.php page. No further function name is disclosed, but the vulnerability is exercised via the delete_wishlist parameter of that URL.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity for data compromise. The EPSS score of <1% suggests a very low likelihood of exploitation under normal circumstances, and the vulnerability is not listed in the CISA KEV catalog. However, the presence of a public exploit and the ability to launch the attack remotely increase operational concern. The combination of medium severity, low EPSS, and a remote attack vector warrants timely remediation.
OpenCVE Enrichment