Impact
SourceCodester Simple and Nice Shopping Cart Script version 1.0 includes a flaw in login.php where the Username field is inserted directly or parameterization. This condition permits a remote attacker to execute arbitrary SQL code, which can lead to unauthorized read or alteration of database contents, and potentially full compromise of the application’s data layer. The flaw is cataloged as CWE‑74 and CWE‑89 and carries a CVSS score of 6.9, indicating moderate severity.
Affected Systems
The affected product is SourceCodester Simple and Nice Shopping Cart Script, version 1.0. Any deployment that includes the /login.php file and has not applied a vendor patch is vulnerable. No other variants or patches are known as of the advisory. The product’s source code is openly available, which may assist attackers in identifying the affected code.
Risk and Exploitability
The exploit is remote, targeting the /login.php endpoint; the EPSS score is below 1 %, indicating a low current probability of exploitation. However, public exploit code exists, and remote access provides a potential attack vector if the endpoint is reachable. The vulnerability is not in the CISA KEV catalog, but the CVSS of 6.9 combined with remote access rises a measurable risk, particularly for deployments that expose the login endpoint without additional controls.
OpenCVE Enrichment