Impact
An injection flaw in the email field of the ajax.php?action=login endpoint allows attackers to execute arbitrary SQL queries. The flaw enables the attacker to read, modify, or delete any data stored in the database, potentially exposing sensitive information or compromising data integrity. If the database user has elevated privileges, the attacker could further gain unauthorized access to the system.
Affected Systems
SourceCodester Photo Share Website, version 1.0, provided by SourceCodester.
Risk and Exploitability
The vulnerability can be exploited remotely through a crafted HTTP request; based on the description, it is inferred that authentication is not required. The exploit has been publicly disclosed, which may increase the likelihood of attacks. The CVSS score of 6.9 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely targeted.
OpenCVE Enrichment