Impact
A code path in the add_judges.php script of itsourcecode Electronic Judging System 1.0 allows an attacker to supply arbitrary SQL statements via the fname parameter. This can enable the execution of unintended queries against the backend database, compromising confidentiality and integrity by allowing unauthorized data retrieval, modification, or deletion. The weakness is classified as CWE-74 and CWE-89.
Affected Systems
Itsourcecode Electronic Judging System version 1.0 is exposed to the flaw. No further version granularity is provided in the current report.
Risk and Exploitability
The CVSS score of 5.3 classifies the issue as moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, the condition that the attack can be initiated remotely and the fact that the exploit has been publicly disclosed mean that an attacker could readily craft a malicious request to the fname argument to cause arbitrary SQL execution if the system remains unpatched.
OpenCVE Enrichment