Impact
A weakness in the Interview Management System 1.0 allows an attacker to manipulate the ID argument in the View.php file, leading to SQL injection. The flaw is exploitable remotely, enabling an attacker to craft malicious input that can read, modify, or delete database contents. The associated weaknesses are identified as CWE-74 and CWE-89, indicating improper handling of user input and unsanitized SQL queries.
Affected Systems
This vulnerability affects code-projects Interview Management System, specifically version 1.0 and any installations that include the View.php component. Users deploying this system should verify the installed version and any related components for potential exposure.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. As the vulnerability is not listed in the CISA KEV catalog, there is no evidence of widespread exploitation. However, because the attack can be initiated remotely through standard HTTP requests, any exposed interface remains a legitimate risk vector. Successful exploitation would allow unauthorized data access or modification.
OpenCVE Enrichment