Impact
The flaw lies in the delete_product handler within the Master.php module; by altering the ID argument, an attacker can inject arbitrary SQL that may read, modify, or delete database contents without further privileges. Because the injection can be performed remotely from the web interface, an adversary could compromise confidentiality, integrity, and availability of the shop’s data.
Affected Systems
SourceCodester Computer Repair Shop Management System version 1.0 is impacted. The vulnerable endpoint is /classes/Master.php?f=delete_product. No other affected versions or products are enumerated in the available data.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. The exploit has been publicly disclosed and can be launched over the network without authentication, raising the risk level. EPSS data is unavailable, and the vulnerability is not yet listed in CISA’s KEV catalog. Attackers could exploit the web interface using manipulated ID values to perform unauthorized database operations.
OpenCVE Enrichment