Impact
The vulnerability, identified as CWE‑497, permits an unauthenticated remote attacker to access a specific page in the Prog Management System and retrieve the database account and password. This disclosure of credential information can enable the attacker to authenticate directly to the underlying database, potentially accessing or altering stored data.
Affected Systems
The CVE data does not specify affected versions or configurations, so it cannot be determined that all installations of PROG MIS:Prog Management System are affected; only systems running the product may be vulnerable.
Risk and Exploitability
The flaw has a CVSS score of 9.3, classifying it as critical, and an EPSS score of less than 1%, indicating that exploitation is currently uncommon. It is not listed in CISA’s KEV catalog. Attackers can simply send an unauthenticated HTTP request to the exposed page; no prior login or special privileges are required.
OpenCVE Enrichment