Impact
Prog Management System contains a classic SQL injection flaw that allows unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. The weakness is identified as CWE‑89.
Affected Systems
All deployments of PROG MIS's Prog Management System are potentially affected. No specific version numbers are listed in the advisory, so a full inventory scan is required to identify vulnerable systems.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability permits unauthenticated remote attackers to send specially crafted requests to the application's exposed interfaces to read database contents, and it is not listed in the CISA KEV catalog. Exploitation would result in unauthorized data exfiltration if unmitigated.
OpenCVE Enrichment