Impact
The student‑registration system contains a SQL injection flaw (CWE‑89) in the changepass.php script that is triggered by manipulating the oldpass argument. The injection involves improper neutralization of special elements used in an SQL command (CWE‑74), allowing an attacker to inject arbitrary SQL statements. This can enable reading, modifying, or deleting data stored in the database, potentially compromising the confidentiality, integrity, and availability of student records and system credentials.
Affected Systems
The affected system is lavkush‑maurya Student‑Registration‑System version 1.0, as distributed in the publicly available source code repository. No other vendors or products are listed as affected.
Risk and Exploitability
The vulnerability is rated a CVSS score of 5.3, indicating moderate severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The attackers can trigger the exploit remotely and the public disclosures show that the vulnerability is exploitable. The lack of vendor remediation increases the risk of successful exploitation.
OpenCVE Enrichment