Impact
The vulnerability, identified as CWE‑497, permits an unauthenticated remote attacker to access a specific page in the Prog Management System and retrieve the database account and password. This disclosure of credential information can enable the attacker to authenticate directly to the underlying database, potentially accessing or altering stored data.
Affected Systems
All installations of PROG MIS Prog Management System are affected by this vulnerability, regardless of deployment configuration.
Risk and Exploitability
The flaw has a CVSS score of 9.3, classifying it as critical, and an EPSS score of less than 1%, indicating that exploitation is currently uncommon. It is not listed in CISA’s KEV catalog. Attackers can simply send an unauthenticated HTTP request to the exposed page; no prior login or special privileges are required.
OpenCVE Enrichment