Impact
The vulnerability originates from an unvalidated UserId parameter in the Admin/EditUser.php module, enabling attackers to inject arbitrary SQL commands. Classified as CWE-74 and CWE-89, this flaw can lead to unauthorized data tampering or extraction.
Affected Systems
Affected is code-projects Online Job Portal version 1.0, particularly the /Admin/EditUser.php script accessed via web requests. Only this version is known to contain the flaw.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while an EPSS score of less than 1% suggests low current exploitation likelihood. The flaw can be triggered remotely through crafted UserId inputs, and public exploits are available, though the portal is not listed in CISA’s KEV catalog. The risk remains until an official update is applied or mitigation measures are implemented.
OpenCVE Enrichment