Impact
The vulnerability exists in chetans9 core-php-admin-panel and is triggered by manipulating the filter_col parameter in customers.php. This flaw permits a remote attacker to inject arbitrary SQL code into the database query, potentially exposing, modifying, or deleting sensitive customer data. The weakness is identified as an injection flaw (CWE‑89) involving improper handling of user input (CWE‑74).
Affected Systems
The issue affects all installations of chetans9 core-php-admin-panel up to the hash 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. No specific version numbers are available due to the product’s rolling release model, and the vendor has not released a patch or update. Any deployment that includes the customers.php endpoint and accepts the filter_col argument is susceptible.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating medium severity, and the EPSS score is not available, meaning an exact exploitation probability cannot be established. Because the exploit can be launched remotely and a public proof‑of‑concept has been published, attackers could feasibly exploit the flaw without prior foothold. The lack of a vendor fix and the continuous release cycle increase the risk of undetected exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Management of this risk requires rapid assessment and mitigation.
OpenCVE Enrichment